CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,294)
page 907 of 1,165| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20389 | — | 0.00 | — | 0.01 | May 15, 2020 | An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without… | ||
| CVE-2020-1941 | — | 0.00 | — | 0.06 | May 14, 2020 | In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. | ||
| CVE-2020-11065 | 0.00 | — | 0.01 | May 13, 2020 | In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; properties being assigned as HTML… | |||
| CVE-2020-11064 | 0.00 | — | 0.01 | May 13, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend… | |||
| CVE-2020-11070 | — | 0.00 | — | 0.01 | May 13, 2020 | The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads… | ||
| CVE-2020-11055 | 0.00 | — | 0.01 | May 7, 2020 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users… | |||
| CVE-2019-17557 | — | 0.00 | — | 0.01 | May 4, 2020 | It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string. | ||
| CVE-2019-20789 | — | 0.00 | — | 0.01 | Apr 26, 2020 | Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies. | ||
| CVE-2020-12245 | — | 0.00 | — | 0.02 | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | ||
| CVE-2020-7642 | 0.00 | — | 0.01 | Apr 22, 2020 | lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript. | |||
| CVE-2020-11888 | — | 0.00 | — | 0.02 | Apr 20, 2020 | python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute. | ||
| CVE-2020-11887 | — | 0.00 | — | 0.01 | Apr 17, 2020 | svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document. | ||
| CVE-2020-5273 | 0.00 | — | 0.01 | Apr 16, 2020 | In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0 | |||
| CVE-2020-11823 | — | 0.00 | — | 0.01 | Apr 16, 2020 | In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account. | ||
| CVE-2020-11001 | 0.00 | — | 0.01 | Apr 14, 2020 | In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could potentially craft a page revision… | |||
| CVE-2020-2176 | 0.00 | — | 0.01 | Apr 7, 2020 | Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to control the values returned from the useMango… | |||
| CVE-2020-2175 | 0.00 | — | 0.01 | Apr 7, 2020 | Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin. | |||
| CVE-2020-2174 | 0.00 | — | 0.01 | Apr 7, 2020 | Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability. | |||
| CVE-2020-2173 | 0.00 | — | 0.01 | Apr 7, 2020 | Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content. | |||
| CVE-2020-10203 | — | 0.00 | — | 0.01 | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows XSS. |
- CVE-2019-20389May 15, 2020risk 0.00cvss —epss 0.01
An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without…
- CVE-2020-1941May 14, 2020risk 0.00cvss —epss 0.06
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
- CVE-2020-11065May 13, 2020risk 0.00cvss —epss 0.01
In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting; properties being assigned as HTML…
- CVE-2020-11064May 13, 2020risk 0.00cvss —epss 0.01
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend…
- CVE-2020-11070May 13, 2020risk 0.00cvss —epss 0.01
The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads…
- CVE-2020-11055May 7, 2020risk 0.00cvss —epss 0.01
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users…
- CVE-2019-17557May 4, 2020risk 0.00cvss —epss 0.01
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
- CVE-2019-20789Apr 26, 2020risk 0.00cvss —epss 0.01
Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
- CVE-2020-12245Apr 24, 2020risk 0.00cvss —epss 0.02
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
- CVE-2020-7642Apr 22, 2020risk 0.00cvss —epss 0.01
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.
- CVE-2020-11888Apr 20, 2020risk 0.00cvss —epss 0.02
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
- CVE-2020-11887Apr 17, 2020risk 0.00cvss —epss 0.01
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
- CVE-2020-5273Apr 16, 2020risk 0.00cvss —epss 0.01
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
- CVE-2020-11823Apr 16, 2020risk 0.00cvss —epss 0.01
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
- CVE-2020-11001Apr 14, 2020risk 0.00cvss —epss 0.01
In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could potentially craft a page revision…
- CVE-2020-2176Apr 7, 2020risk 0.00cvss —epss 0.01
Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to control the values returned from the useMango…
- CVE-2020-2175Apr 7, 2020risk 0.00cvss —epss 0.01
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin.
- CVE-2020-2174Apr 7, 2020risk 0.00cvss —epss 0.01
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
- CVE-2020-2173Apr 7, 2020risk 0.00cvss —epss 0.01
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.
- CVE-2020-10203Apr 1, 2020risk 0.00cvss —epss 0.01
Sonatype Nexus Repository before 3.21.2 allows XSS.