CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 912 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15477 | — | 0.00 | — | 0.00 | Aug 23, 2019 | Jooby before 1.6.4 has XSS via the default error handler. | ||
| CVE-2019-15074 | — | 0.00 | — | 0.01 | Aug 21, 2019 | The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user… | ||
| CVE-2018-20975 | — | 0.00 | — | 0.00 | Aug 20, 2019 | Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb. | ||
| CVE-2018-20858 | — | 0.00 | — | 0.00 | Aug 9, 2019 | Recommender before 2018-07-18 allows XSS. | ||
| CVE-2018-20962 | — | 0.00 | — | 0.00 | Aug 8, 2019 | The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type. | ||
| CVE-2019-12397 | — | 0.00 | — | 0.02 | Aug 8, 2019 | Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix. | ||
| CVE-2019-14772 | — | 0.00 | — | 0.00 | Aug 8, 2019 | verdaccio before 3.12.0 allows XSS. | ||
| CVE-2019-10373 | 0.00 | — | 0.00 | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins. | |||
| CVE-2019-10374 | 0.00 | — | 0.00 | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI. | |||
| CVE-2019-10376 | 0.00 | — | 0.00 | Aug 7, 2019 | A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin. | |||
| CVE-2019-12950 | — | 0.00 | — | 0.00 | Aug 6, 2019 | An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. | ||
| CVE-2019-14653 | — | 0.00 | — | 0.00 | Aug 3, 2019 | pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. | ||
| CVE-2019-7853 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notifications configuration in the Magento admin panel. | |||
| CVE-2019-7945 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency… | |||
| CVE-2019-7944 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with… | |||
| CVE-2019-7939 | 0.00 | — | 0.00 | Aug 2, 2019 | A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript… | |||
| CVE-2019-7938 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated… | |||
| CVE-2019-7937 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to store product attributes to inject malicious… | |||
| CVE-2019-7936 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious… | |||
| CVE-2019-7935 | 0.00 | — | 0.00 | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated… |
- CVE-2019-15477Aug 23, 2019risk 0.00cvss —epss 0.00
Jooby before 1.6.4 has XSS via the default error handler.
- CVE-2019-15074Aug 21, 2019risk 0.00cvss —epss 0.01
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user…
- CVE-2018-20975Aug 20, 2019risk 0.00cvss —epss 0.00
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
- CVE-2018-20858Aug 9, 2019risk 0.00cvss —epss 0.00
Recommender before 2018-07-18 allows XSS.
- CVE-2018-20962Aug 8, 2019risk 0.00cvss —epss 0.00
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
- CVE-2019-12397Aug 8, 2019risk 0.00cvss —epss 0.02
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
- CVE-2019-14772Aug 8, 2019risk 0.00cvss —epss 0.00
verdaccio before 3.12.0 allows XSS.
- CVE-2019-10373Aug 7, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
- CVE-2019-10374Aug 7, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.
- CVE-2019-10376Aug 7, 2019risk 0.00cvss —epss 0.00
A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
- CVE-2019-12950Aug 6, 2019risk 0.00cvss —epss 0.00
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.
- CVE-2019-14653Aug 3, 2019risk 0.00cvss —epss 0.00
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
- CVE-2019-7853Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the tax notifications configuration in the Magento admin panel.
- CVE-2019-7945Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency…
- CVE-2019-7944Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with…
- CVE-2019-7939Aug 2, 2019risk 0.00cvss —epss 0.00
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript…
- CVE-2019-7938Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated…
- CVE-2019-7937Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to store product attributes to inject malicious…
- CVE-2019-7936Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious…
- CVE-2019-7935Aug 2, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated…