CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 911 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16173 | — | 0.00 | — | 0.01 | Sep 9, 2019 | LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php, | ||
| CVE-2019-16148 | — | 0.00 | — | 0.00 | Sep 9, 2019 | Sakai through 12.6 allows XSS via a chat user name. | ||
| CVE-2019-16146 | — | 0.00 | — | 0.00 | Sep 9, 2019 | Gophish through 0.8.0 allows XSS via a username. | ||
| CVE-2019-16130 | — | 0.00 | — | 0.00 | Sep 9, 2019 | YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html. | ||
| CVE-2019-16126 | — | 0.00 | — | 0.01 | Sep 9, 2019 | Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images. | ||
| CVE-2018-11198 | — | 0.00 | — | 0.00 | Sep 6, 2019 | An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json. | ||
| CVE-2019-13209 | — | 0.00 | — | 0.00 | Sep 4, 2019 | Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the… | ||
| CVE-2019-15782 | — | 0.00 | — | 0.00 | Aug 29, 2019 | WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name. | ||
| CVE-2019-10383 | 0.00 | — | 0.00 | Aug 28, 2019 | A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages. | |||
| CVE-2019-15479 | — | 0.00 | — | 0.00 | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via dashboard.ts. | ||
| CVE-2019-15489 | — | 0.00 | — | 0.00 | Aug 26, 2019 | laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. | ||
| CVE-2019-15532 | — | 0.00 | — | 0.00 | Aug 26, 2019 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. | ||
| CVE-2019-15478 | — | 0.00 | — | 0.00 | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via logic.ts. | ||
| CVE-2019-15482 | — | 0.00 | — | 0.00 | Aug 23, 2019 | selectize-plugin-a11y before 1.1.0 has XSS via the msg field. | ||
| CVE-2019-15488 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. | ||
| CVE-2019-15486 | — | 0.00 | — | 0.00 | Aug 23, 2019 | django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. | ||
| CVE-2019-15485 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. | ||
| CVE-2019-15484 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Bolt before 3.6.10 has XSS via an image's alt or title field. | ||
| CVE-2019-15483 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Bolt before 3.6.10 has XSS via a title that is mishandled in the system log. | ||
| CVE-2019-15481 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Kimai v2 before 1.1 has XSS via a timesheet description. |
- CVE-2019-16173Sep 9, 2019risk 0.00cvss —epss 0.01
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
- CVE-2019-16148Sep 9, 2019risk 0.00cvss —epss 0.00
Sakai through 12.6 allows XSS via a chat user name.
- CVE-2019-16146Sep 9, 2019risk 0.00cvss —epss 0.00
Gophish through 0.8.0 allows XSS via a username.
- CVE-2019-16130Sep 9, 2019risk 0.00cvss —epss 0.00
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
- CVE-2019-16126Sep 9, 2019risk 0.00cvss —epss 0.01
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
- CVE-2018-11198Sep 6, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
- CVE-2019-13209Sep 4, 2019risk 0.00cvss —epss 0.00
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the…
- CVE-2019-15782Aug 29, 2019risk 0.00cvss —epss 0.00
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
- CVE-2019-10383Aug 28, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
- CVE-2019-15479Aug 26, 2019risk 0.00cvss —epss 0.00
Status Board 1.1.81 has reflected XSS via dashboard.ts.
- CVE-2019-15489Aug 26, 2019risk 0.00cvss —epss 0.00
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
- CVE-2019-15532Aug 26, 2019risk 0.00cvss —epss 0.00
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
- CVE-2019-15478Aug 26, 2019risk 0.00cvss —epss 0.00
Status Board 1.1.81 has reflected XSS via logic.ts.
- CVE-2019-15482Aug 23, 2019risk 0.00cvss —epss 0.00
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
- CVE-2019-15488Aug 23, 2019risk 0.00cvss —epss 0.00
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
- CVE-2019-15486Aug 23, 2019risk 0.00cvss —epss 0.00
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
- CVE-2019-15485Aug 23, 2019risk 0.00cvss —epss 0.00
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
- CVE-2019-15484Aug 23, 2019risk 0.00cvss —epss 0.00
Bolt before 3.6.10 has XSS via an image's alt or title field.
- CVE-2019-15483Aug 23, 2019risk 0.00cvss —epss 0.00
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
- CVE-2019-15481Aug 23, 2019risk 0.00cvss —epss 0.00
Kimai v2 before 1.1 has XSS via a timesheet description.