VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 908 of 1,159
  • CVE-2019-8128Nov 5, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.

  • CVE-2019-8120Nov 5, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email…

  • CVE-2019-8117Nov 5, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.

  • CVE-2019-8115Nov 5, 2019
    risk 0.00cvss epss 0.02

    A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.

  • CVE-2019-8092Nov 5, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.

  • CVE-2010-3672Nov 5, 2019
    risk 0.00cvss epss 0.00

    TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.

  • CVE-2010-3660Nov 1, 2019
    risk 0.00cvss epss 0.00

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.

  • CVE-2019-18656Oct 31, 2019
    risk 0.00cvss epss 0.00

    Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.

  • CVE-2018-21030Oct 31, 2019
    risk 0.00cvss epss 0.00

    Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

  • CVE-2019-12417Oct 30, 2019
    risk 0.00cvss epss 0.01

    A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

  • CVE-2019-18413Oct 24, 2019
    risk 0.00cvss epss 0.00

    In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this…

  • CVE-2019-17606Oct 23, 2019
    risk 0.00cvss epss 0.00

    The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.

  • CVE-2019-15587Oct 22, 2019
    risk 0.00cvss epss 0.02

    In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

  • CVE-2019-17576Oct 16, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

  • CVE-2019-17577Oct 16, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

  • CVE-2019-17578Oct 16, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

  • CVE-2019-17625Oct 16, 2019
    risk 0.00cvss epss 0.05

    There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for…

  • CVE-2017-1002201Oct 15, 2019
    risk 0.00cvss epss 0.01

    In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially…

  • CVE-2019-17223Oct 15, 2019
    risk 0.00cvss epss 0.00

    There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

  • CVE-2019-17496Oct 10, 2019
    risk 0.00cvss epss 0.00

    Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.