VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 91 of 2,331
  • CVE-2025-40772HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page. …

  • CVE-2025-26064HigJul 31, 2025
    risk 0.48cvss 7.3epss 0.01

    A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.

  • CVE-2025-6248HigJul 17, 2025
    risk 0.48cvss 7.4epss 0.00

    A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.

  • CVE-2025-27447HigJul 3, 2025
    risk 0.48cvss 7.4epss 0.00

    The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the link.

  • CVE-2025-49137HigJun 9, 2025
    risk 0.48cvss 8.5epss 0.00

    HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user…

  • CVE-2024-27781HigFeb 11, 2025
    risk 0.48cvss 7.1epss 0.28

    An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2024-11916HigJan 8, 2025
    risk 0.48cvss 7.4epss 0.00

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This makes it possible for authenticated…

  • CVE-2024-36249HigNov 26, 2024
    risk 0.48cvss 7.4epss 0.01

    Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of…

  • CVE-2024-47801HigOct 25, 2024
    risk 0.48cvss 7.4epss 0.00

    Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

  • CVE-2024-6530HigOct 10, 2024
    risk 0.48cvss 7.3epss 0.02

    A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under…

  • CVE-2024-40509HigSep 27, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.

  • CVE-2024-40512HigSep 27, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.

  • CVE-2024-40511HigSep 27, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

  • CVE-2024-40508HigSep 26, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.

  • CVE-2024-40507HigSep 26, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

  • CVE-2024-40506HigSep 26, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

  • CVE-2024-28739HigAug 6, 2024
    risk 0.48cvss 7.2epss 0.19

    An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

  • CVE-2024-3667HigJun 5, 2024
    risk 0.48cvss 7.4epss 0.00

    The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping on user supplied attributes. This…

  • CVE-2024-34224HigMay 14, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

  • CVE-2024-33306HigMay 1, 2024
    risk 0.48cvss 7.4epss 0.01

    SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.