VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 911 of 1,159
  • CVE-2019-16173Sep 9, 2019
    risk 0.00cvss epss 0.01

    LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,

  • CVE-2019-16148Sep 9, 2019
    risk 0.00cvss epss 0.00

    Sakai through 12.6 allows XSS via a chat user name.

  • CVE-2019-16146Sep 9, 2019
    risk 0.00cvss epss 0.00

    Gophish through 0.8.0 allows XSS via a username.

  • CVE-2019-16130Sep 9, 2019
    risk 0.00cvss epss 0.00

    YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.

  • CVE-2019-16126Sep 9, 2019
    risk 0.00cvss epss 0.01

    Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.

  • CVE-2018-11198Sep 6, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.

  • CVE-2019-13209Sep 4, 2019
    risk 0.00cvss epss 0.00

    Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the…

  • CVE-2019-15782Aug 29, 2019
    risk 0.00cvss epss 0.00

    WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.

  • CVE-2019-10383Aug 28, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.

  • CVE-2019-15479Aug 26, 2019
    risk 0.00cvss epss 0.00

    Status Board 1.1.81 has reflected XSS via dashboard.ts.

  • CVE-2019-15489Aug 26, 2019
    risk 0.00cvss epss 0.00

    laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.

  • CVE-2019-15532Aug 26, 2019
    risk 0.00cvss epss 0.00

    CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.

  • CVE-2019-15478Aug 26, 2019
    risk 0.00cvss epss 0.00

    Status Board 1.1.81 has reflected XSS via logic.ts.

  • CVE-2019-15482Aug 23, 2019
    risk 0.00cvss epss 0.00

    selectize-plugin-a11y before 1.1.0 has XSS via the msg field.

  • CVE-2019-15488Aug 23, 2019
    risk 0.00cvss epss 0.00

    Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.

  • CVE-2019-15486Aug 23, 2019
    risk 0.00cvss epss 0.00

    django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.

  • CVE-2019-15485Aug 23, 2019
    risk 0.00cvss epss 0.00

    Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

  • CVE-2019-15484Aug 23, 2019
    risk 0.00cvss epss 0.00

    Bolt before 3.6.10 has XSS via an image's alt or title field.

  • CVE-2019-15483Aug 23, 2019
    risk 0.00cvss epss 0.00

    Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

  • CVE-2019-15481Aug 23, 2019
    risk 0.00cvss epss 0.00

    Kimai v2 before 1.1 has XSS via a timesheet description.