CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 908 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-8128 | 0.00 | — | 0.00 | Nov 5, 2019 | A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website. | |||
| CVE-2019-8120 | 0.00 | — | 0.00 | Nov 5, 2019 | A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email… | |||
| CVE-2019-8117 | 0.00 | — | 0.00 | Nov 5, 2019 | A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification. | |||
| CVE-2019-8115 | 0.00 | — | 0.02 | Nov 5, 2019 | A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation. | |||
| CVE-2019-8092 | 0.00 | — | 0.00 | Nov 5, 2019 | A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview. | |||
| CVE-2010-3672 | — | 0.00 | — | 0.00 | Nov 5, 2019 | TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension. | ||
| CVE-2010-3660 | — | 0.00 | — | 0.00 | Nov 1, 2019 | TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend. | ||
| CVE-2019-18656 | — | 0.00 | — | 0.00 | Oct 31, 2019 | Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements. | ||
| CVE-2018-21030 | — | 0.00 | — | 0.00 | Oct 31, 2019 | Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document. | ||
| CVE-2019-12417 | — | 0.00 | — | 0.01 | Oct 30, 2019 | A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process. | ||
| CVE-2019-18413 | — | 0.00 | — | 0.00 | Oct 24, 2019 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this… | ||
| CVE-2019-17606 | — | 0.00 | — | 0.00 | Oct 23, 2019 | The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post. | ||
| CVE-2019-15587 | — | 0.00 | — | 0.02 | Oct 22, 2019 | In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. | ||
| CVE-2019-17576 | — | 0.00 | — | 0.00 | Oct 16, 2019 | An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field. | ||
| CVE-2019-17577 | — | 0.00 | — | 0.00 | Oct 16, 2019 | An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field. | ||
| CVE-2019-17578 | — | 0.00 | — | 0.00 | Oct 16, 2019 | An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field. | ||
| CVE-2019-17625 | — | 0.00 | — | 0.05 | Oct 16, 2019 | There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for… | ||
| CVE-2017-1002201 | 0.00 | — | 0.01 | Oct 15, 2019 | In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially… | |||
| CVE-2019-17223 | — | 0.00 | — | 0.00 | Oct 15, 2019 | There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. | ||
| CVE-2019-17496 | — | 0.00 | — | 0.00 | Oct 10, 2019 | Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. |
- CVE-2019-8128Nov 5, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.
- CVE-2019-8120Nov 5, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email…
- CVE-2019-8117Nov 5, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.
- CVE-2019-8115Nov 5, 2019risk 0.00cvss —epss 0.02
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.
- CVE-2019-8092Nov 5, 2019risk 0.00cvss —epss 0.00
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.
- CVE-2010-3672Nov 5, 2019risk 0.00cvss —epss 0.00
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.
- CVE-2010-3660Nov 1, 2019risk 0.00cvss —epss 0.00
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
- CVE-2019-18656Oct 31, 2019risk 0.00cvss —epss 0.00
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.
- CVE-2018-21030Oct 31, 2019risk 0.00cvss —epss 0.00
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
- CVE-2019-12417Oct 30, 2019risk 0.00cvss —epss 0.01
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
- CVE-2019-18413Oct 24, 2019risk 0.00cvss —epss 0.00
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this…
- CVE-2019-17606Oct 23, 2019risk 0.00cvss —epss 0.00
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
- CVE-2019-15587Oct 22, 2019risk 0.00cvss —epss 0.02
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
- CVE-2019-17576Oct 16, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
- CVE-2019-17577Oct 16, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
- CVE-2019-17578Oct 16, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
- CVE-2019-17625Oct 16, 2019risk 0.00cvss —epss 0.05
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for…
- CVE-2017-1002201Oct 15, 2019risk 0.00cvss —epss 0.01
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially…
- CVE-2019-17223Oct 15, 2019risk 0.00cvss —epss 0.00
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
- CVE-2019-17496Oct 10, 2019risk 0.00cvss —epss 0.00
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.