VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,294)

page 902 of 1,165
  • CVE-2020-15155Aug 28, 2020
    risk 0.00cvss epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

  • CVE-2020-15154Aug 28, 2020
    risk 0.00cvss epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php,…

  • CVE-2020-14042Aug 25, 2020
    risk 0.00cvss epss 0.01

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the…

  • CVE-2020-15119Aug 19, 2020
    risk 0.00cvss epss 0.01

    In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

  • CVE-2020-12648Aug 14, 2020
    risk 0.00cvss epss 0.02

    A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.

  • CVE-2020-13278Aug 12, 2020
    risk 0.00cvss epss 0.01

    Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request.

  • CVE-2020-2236Aug 12, 2020
    risk 0.00cvss epss 0.01

    Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.

  • CVE-2020-2231Aug 12, 2020
    risk 0.00cvss epss 0.05

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the…

  • CVE-2020-2229Aug 12, 2020
    risk 0.00cvss epss 0.07

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2020-16266Aug 12, 2020
    risk 0.00cvss epss 0.01

    An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently…

  • CVE-2020-17480Aug 10, 2020
    risk 0.00cvss epss 0.01

    TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.

  • CVE-2020-15138Aug 7, 2020
    risk 0.00cvss epss 0.02

    Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the…

  • CVE-2020-16095Jul 29, 2020
    risk 0.00cvss epss 0.01

    The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.

  • CVE-2020-9691Jul 29, 2020
    risk 0.00cvss epss 0.06

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-13971Jul 28, 2020
    risk 0.00cvss epss 0.01

    In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

  • CVE-2020-11110Jul 27, 2020
    risk 0.00cvss epss 0.09

    Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

  • CVE-2020-15881Jul 23, 2020
    risk 0.00cvss epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the key name.

  • CVE-2020-15883Jul 23, 2020
    risk 0.00cvss epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported).

  • CVE-2020-15885Jul 23, 2020
    risk 0.00cvss epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.

  • CVE-2020-9665Jul 22, 2020
    risk 0.00cvss epss 0.01

    Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.