CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 909 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17495 | — | 0.00 | — | 0.12 | Oct 10, 2019 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product… | ||
| CVE-2019-17433 | — | 0.00 | — | 0.00 | Oct 10, 2019 | z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen. | ||
| CVE-2019-10756 | — | 0.00 | — | 0.00 | Oct 8, 2019 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. | ||
| CVE-2019-17203 | — | 0.00 | — | 0.00 | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. | ||
| CVE-2019-17204 | — | 0.00 | — | 0.00 | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. | ||
| CVE-2019-17205 | — | 0.00 | — | 0.00 | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. | ||
| CVE-2019-17091 | — | 0.00 | — | 0.06 | Oct 2, 2019 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | ||
| CVE-2019-10432 | 0.00 | — | 0.00 | Oct 1, 2019 | Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those. | |||
| CVE-2019-16688 | — | 0.00 | — | 0.00 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.) | ||
| CVE-2019-16687 | — | 0.00 | — | 0.00 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation. | ||
| CVE-2019-16686 | — | 0.00 | — | 0.00 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin. | ||
| CVE-2019-16685 | — | 0.00 | — | 0.00 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation. | ||
| CVE-2019-13376 | — | 0.00 | — | 0.00 | Sep 27, 2019 | phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS | ||
| CVE-2019-14272 | — | 0.00 | — | 0.00 | Sep 26, 2019 | In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS. | ||
| CVE-2019-16904 | — | 0.00 | — | 0.00 | Sep 26, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.) | ||
| CVE-2017-18635 | — | 0.00 | — | 0.07 | Sep 25, 2019 | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. | ||
| CVE-2019-12205 | — | 0.00 | — | 0.00 | Sep 25, 2019 | SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS. | ||
| CVE-2019-10406 | 0.00 | — | 0.00 | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission. | |||
| CVE-2019-10401 | 0.00 | — | 0.00 | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure). | |||
| CVE-2019-10402 | 0.00 | — | 0.00 | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents. |
- CVE-2019-17495Oct 10, 2019risk 0.00cvss —epss 0.12
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…
- CVE-2019-17433Oct 10, 2019risk 0.00cvss —epss 0.00
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
- CVE-2019-10756Oct 8, 2019risk 0.00cvss —epss 0.00
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
- CVE-2019-17203Oct 5, 2019risk 0.00cvss —epss 0.00
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
- CVE-2019-17204Oct 5, 2019risk 0.00cvss —epss 0.00
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
- CVE-2019-17205Oct 5, 2019risk 0.00cvss —epss 0.00
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
- CVE-2019-17091Oct 2, 2019risk 0.00cvss —epss 0.06
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
- CVE-2019-10432Oct 1, 2019risk 0.00cvss —epss 0.00
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
- CVE-2019-16688Sep 27, 2019risk 0.00cvss —epss 0.00
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)
- CVE-2019-16687Sep 27, 2019risk 0.00cvss —epss 0.00
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
- CVE-2019-16686Sep 27, 2019risk 0.00cvss —epss 0.00
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
- CVE-2019-16685Sep 27, 2019risk 0.00cvss —epss 0.00
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
- CVE-2019-13376Sep 27, 2019risk 0.00cvss —epss 0.00
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
- CVE-2019-14272Sep 26, 2019risk 0.00cvss —epss 0.00
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
- CVE-2019-16904Sep 26, 2019risk 0.00cvss —epss 0.00
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
- CVE-2017-18635Sep 25, 2019risk 0.00cvss —epss 0.07
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
- CVE-2019-12205Sep 25, 2019risk 0.00cvss —epss 0.00
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
- CVE-2019-10406Sep 25, 2019risk 0.00cvss —epss 0.00
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
- CVE-2019-10401Sep 25, 2019risk 0.00cvss —epss 0.00
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure).
- CVE-2019-10402Sep 25, 2019risk 0.00cvss —epss 0.00
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.