VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 9 of 2,331
  • CVE-2023-27335CriMay 3, 2024
    risk 0.62cvss 9.6epss 0.01

    Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that…

  • CVE-2024-4405CriMay 2, 2024
    risk 0.62cvss 9.6epss 0.01

    Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability…

  • CVE-2024-32340CriApr 17, 2024
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the WEBSITE TITLE parameter under the Menu module.

  • CVE-2024-31650CriApr 15, 2024
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

  • CVE-2024-22718CriApr 11, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

  • CVE-2024-24276CriMar 5, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.

  • CVE-2024-24275CriMar 5, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.

  • CVE-2024-26269CriFeb 21, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject…

  • CVE-2023-42498CriFeb 21, 2024
    risk 0.62cvss 9.6epss 0.01

    Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the…

  • CVE-2023-42496CriFeb 21, 2024
    risk 0.62cvss 9.6epss 0.01

    Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or…

  • CVE-2024-25147CriFeb 21, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary…

  • CVE-2024-25145CriFeb 7, 2024
    risk 0.62cvss 9.6epss 0.01

    Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported…

  • CVE-2023-49657CriJan 23, 2024
    risk 0.62cvss 9.6epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored XSS. For 2.X versions,…

  • CVE-2023-47797CriNov 17, 2023
    risk 0.62cvss 9.6epss 0.01

    Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.

  • CVE-2023-1717CriNov 1, 2023
    risk 0.62cvss 9.6epss 0.01

    Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has…

  • CVE-2023-45992CriOct 19, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack,…

  • CVE-2022-37830CriOct 19, 2023
    risk 0.62cvss 9.6epss 0.01

    Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-42497CriOct 17, 2023
    risk 0.62cvss 9.6epss 0.00

    Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_por…

  • CVE-2023-38888CriSep 20, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

  • CVE-2023-30319CriJul 6, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.