VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 914 of 1,159
  • CVE-2019-7862Aug 2, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

  • CVE-2019-14517Aug 1, 2019
    risk 0.00cvss epss 0.00

    pandao Editor.md 1.5.0 allows XSS via the Javascript: string.

  • CVE-2019-10360Jul 31, 2019
    risk 0.00cvss epss 0.00

    A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

  • CVE-2019-5457Jul 30, 2019
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

  • CVE-2019-5458Jul 30, 2019
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

  • CVE-2019-1020005Jul 29, 2019
    risk 0.00cvss epss 0.00

    invenio-communities before 1.0.0a20 allows XSS.

  • CVE-2019-1020003Jul 29, 2019
    risk 0.00cvss epss 0.00

    invenio-records before 1.2.2 allows XSS.

  • CVE-2019-1020019Jul 29, 2019
    risk 0.00cvss epss 0.00

    invenio-previewer before 1.0.0a12 allows XSS.

  • CVE-2019-14315Jul 28, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.

  • CVE-2019-1010199Jul 23, 2019
    risk 0.00cvss epss 0.00

    ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is…

  • CVE-2019-1010113Jul 19, 2019
    risk 0.00cvss epss 0.00

    Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted…

  • CVE-2019-13970Jul 19, 2019
    risk 0.00cvss epss 0.01

    In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.

  • CVE-2019-1010261Jul 18, 2019
    risk 0.00cvss epss 0.00

    Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…

  • CVE-2019-13647Jul 18, 2019
    risk 0.00cvss epss 0.00

    Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access…

  • CVE-2019-13646Jul 18, 2019
    risk 0.00cvss epss 0.00

    Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability

  • CVE-2019-13645Jul 18, 2019
    risk 0.00cvss epss 0.00

    Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access…

  • CVE-2019-13644Jul 18, 2019
    risk 0.00cvss epss 0.00

    Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must…

  • CVE-2019-1010091Jul 17, 2019
    risk 0.00cvss epss 0.01

    tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.

  • CVE-2019-1010016Jul 15, 2019
    risk 0.00cvss epss 0.00

    Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

  • CVE-2019-1010314Jul 11, 2019
    risk 0.00cvss epss 0.00

    Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.