CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 910 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10406 | 0.00 | — | 0.00 | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission. | |||
| CVE-2019-10402 | 0.00 | — | 0.00 | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents. | |||
| CVE-2019-10401 | 0.00 | — | 0.00 | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure). | |||
| CVE-2019-10405 | 0.00 | — | 0.82 | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly. | |||
| CVE-2019-16725 | — | 0.00 | — | 0.04 | Sep 24, 2019 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. | ||
| CVE-2019-16751 | — | 0.00 | — | 0.00 | Sep 24, 2019 | An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's… | ||
| CVE-2019-16728 | — | 0.00 | — | 0.01 | Sep 24, 2019 | DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. | ||
| CVE-2019-12407 | — | 0.00 | — | 0.04 | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and… | ||
| CVE-2019-10090 | — | 0.00 | — | 0.04 | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive… | ||
| CVE-2019-12404 | — | 0.00 | — | 0.04 | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive… | ||
| CVE-2019-10089 | — | 0.00 | — | 0.04 | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive… | ||
| CVE-2019-10087 | — | 0.00 | — | 0.04 | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive… | ||
| CVE-2019-15138 | — | 0.00 | — | 0.00 | Sep 20, 2019 | The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL. | ||
| CVE-2018-11200 | — | 0.00 | — | 0.00 | Sep 20, 2019 | An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field. | ||
| CVE-2019-16197 | — | 0.00 | — | 0.00 | Sep 16, 2019 | In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS. | ||
| CVE-2019-10396 | 0.00 | — | 0.00 | Sep 12, 2019 | Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions. | |||
| CVE-2019-10395 | 0.00 | — | 0.00 | Sep 12, 2019 | Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties. | |||
| CVE-2019-16145 | — | 0.00 | — | 0.00 | Sep 9, 2019 | The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption. | ||
| CVE-2019-16147 | — | 0.00 | — | 0.00 | Sep 9, 2019 | Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib. | ||
| CVE-2019-16172 | — | 0.00 | — | 0.01 | Sep 9, 2019 | LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion. |
- CVE-2019-10406Sep 25, 2019risk 0.00cvss —epss 0.00
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
- CVE-2019-10402Sep 25, 2019risk 0.00cvss —epss 0.00
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
- CVE-2019-10401Sep 25, 2019risk 0.00cvss —epss 0.00
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure).
- CVE-2019-10405Sep 25, 2019risk 0.00cvss —epss 0.82
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.
- CVE-2019-16725Sep 24, 2019risk 0.00cvss —epss 0.04
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
- CVE-2019-16751Sep 24, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's…
- CVE-2019-16728Sep 24, 2019risk 0.00cvss —epss 0.01
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
- CVE-2019-12407Sep 23, 2019risk 0.00cvss —epss 0.04
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and…
- CVE-2019-10090Sep 23, 2019risk 0.00cvss —epss 0.04
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…
- CVE-2019-12404Sep 23, 2019risk 0.00cvss —epss 0.04
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…
- CVE-2019-10089Sep 23, 2019risk 0.00cvss —epss 0.04
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…
- CVE-2019-10087Sep 23, 2019risk 0.00cvss —epss 0.04
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…
- CVE-2019-15138Sep 20, 2019risk 0.00cvss —epss 0.00
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
- CVE-2018-11200Sep 20, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
- CVE-2019-16197Sep 16, 2019risk 0.00cvss —epss 0.00
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
- CVE-2019-10396Sep 12, 2019risk 0.00cvss —epss 0.00
Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions.
- CVE-2019-10395Sep 12, 2019risk 0.00cvss —epss 0.00
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.
- CVE-2019-16145Sep 9, 2019risk 0.00cvss —epss 0.00
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
- CVE-2019-16147Sep 9, 2019risk 0.00cvss —epss 0.00
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
- CVE-2019-16172Sep 9, 2019risk 0.00cvss —epss 0.01
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.