CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,294)
page 902 of 1,165| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15155 | 0.00 | — | 0.01 | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7. | |||
| CVE-2020-15154 | 0.00 | — | 0.01 | Aug 28, 2020 | baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php,… | |||
| CVE-2020-14042 | — | 0.00 | — | 0.01 | Aug 25, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the… | ||
| CVE-2020-15119 | 0.00 | — | 0.01 | Aug 19, 2020 | In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks. | |||
| CVE-2020-12648 | — | 0.00 | — | 0.02 | Aug 14, 2020 | A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode. | ||
| CVE-2020-13278 | 0.00 | — | 0.01 | Aug 12, 2020 | Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request. | |||
| CVE-2020-2236 | 0.00 | — | 0.01 | Aug 12, 2020 | Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission. | |||
| CVE-2020-2231 | 0.00 | — | 0.05 | Aug 12, 2020 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the… | |||
| CVE-2020-2229 | 0.00 | — | 0.07 | Aug 12, 2020 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability. | |||
| CVE-2020-16266 | — | 0.00 | — | 0.01 | Aug 12, 2020 | An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently… | ||
| CVE-2020-17480 | — | 0.00 | — | 0.01 | Aug 10, 2020 | TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor. | ||
| CVE-2020-15138 | 0.00 | — | 0.02 | Aug 7, 2020 | Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the… | |||
| CVE-2020-16095 | — | 0.00 | — | 0.01 | Jul 29, 2020 | The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS. | ||
| CVE-2020-9691 | 0.00 | — | 0.06 | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution. | |||
| CVE-2020-13971 | — | 0.00 | — | 0.01 | Jul 28, 2020 | In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication. | ||
| CVE-2020-11110 | — | 0.00 | — | 0.09 | Jul 27, 2020 | Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | ||
| CVE-2020-15881 | — | 0.00 | — | 0.01 | Jul 23, 2020 | A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the key name. | ||
| CVE-2020-15883 | — | 0.00 | — | 0.01 | Jul 23, 2020 | A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported). | ||
| CVE-2020-15885 | — | 0.00 | — | 0.01 | Jul 23, 2020 | A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment. | ||
| CVE-2020-9665 | 0.00 | — | 0.01 | Jul 22, 2020 | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
- CVE-2020-15155Aug 28, 2020risk 0.00cvss —epss 0.01
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
- CVE-2020-15154Aug 28, 2020risk 0.00cvss —epss 0.01
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php,…
- CVE-2020-14042Aug 25, 2020risk 0.00cvss —epss 0.01
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the…
- CVE-2020-15119Aug 19, 2020risk 0.00cvss —epss 0.01
In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.
- CVE-2020-12648Aug 14, 2020risk 0.00cvss —epss 0.02
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
- CVE-2020-13278Aug 12, 2020risk 0.00cvss —epss 0.01
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request.
- CVE-2020-2236Aug 12, 2020risk 0.00cvss —epss 0.01
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.
- CVE-2020-2231Aug 12, 2020risk 0.00cvss —epss 0.05
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the…
- CVE-2020-2229Aug 12, 2020risk 0.00cvss —epss 0.07
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
- CVE-2020-16266Aug 12, 2020risk 0.00cvss —epss 0.01
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently…
- CVE-2020-17480Aug 10, 2020risk 0.00cvss —epss 0.01
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
- CVE-2020-15138Aug 7, 2020risk 0.00cvss —epss 0.02
Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the…
- CVE-2020-16095Jul 29, 2020risk 0.00cvss —epss 0.01
The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
- CVE-2020-9691Jul 29, 2020risk 0.00cvss —epss 0.06
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-13971Jul 28, 2020risk 0.00cvss —epss 0.01
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
- CVE-2020-11110Jul 27, 2020risk 0.00cvss —epss 0.09
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
- CVE-2020-15881Jul 23, 2020risk 0.00cvss —epss 0.01
A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the key name.
- CVE-2020-15883Jul 23, 2020risk 0.00cvss —epss 0.01
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported).
- CVE-2020-15885Jul 23, 2020risk 0.00cvss —epss 0.01
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.
- CVE-2020-9665Jul 22, 2020risk 0.00cvss —epss 0.01
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.