VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 912 of 1,159
  • CVE-2019-15477Aug 23, 2019
    risk 0.00cvss epss 0.00

    Jooby before 1.6.4 has XSS via the default error handler.

  • CVE-2019-15074Aug 21, 2019
    risk 0.00cvss epss 0.01

    The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user…

  • CVE-2018-20975Aug 20, 2019
    risk 0.00cvss epss 0.00

    Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.

  • CVE-2018-20858Aug 9, 2019
    risk 0.00cvss epss 0.00

    Recommender before 2018-07-18 allows XSS.

  • CVE-2018-20962Aug 8, 2019
    risk 0.00cvss epss 0.00

    The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.

  • CVE-2019-12397Aug 8, 2019
    risk 0.00cvss epss 0.02

    Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.

  • CVE-2019-14772Aug 8, 2019
    risk 0.00cvss epss 0.00

    verdaccio before 3.12.0 allows XSS.

  • CVE-2019-10373Aug 7, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

  • CVE-2019-10374Aug 7, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.

  • CVE-2019-10376Aug 7, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

  • CVE-2019-12950Aug 6, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.

  • CVE-2019-14653Aug 3, 2019
    risk 0.00cvss epss 0.00

    pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.

  • CVE-2019-7853Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notifications configuration in the Magento admin panel.

  • CVE-2019-7945Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency…

  • CVE-2019-7944Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with…

  • CVE-2019-7939Aug 2, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript…

  • CVE-2019-7938Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated…

  • CVE-2019-7937Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to store product attributes to inject malicious…

  • CVE-2019-7936Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious…

  • CVE-2019-7935Aug 2, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated…