CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 915 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10346 | 0.00 | — | 0.00 | Jul 11, 2019 | A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin. | |||
| CVE-2019-10349 | 0.00 | — | 0.01 | Jul 11, 2019 | A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins. | |||
| CVE-2019-13506 | — | 0.00 | — | 0.01 | Jul 11, 2019 | @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS. | ||
| CVE-2019-12471 | — | 0.00 | — | 0.00 | Jul 10, 2019 | Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | ||
| CVE-2017-6217 | — | 0.00 | — | 0.00 | Jul 10, 2019 | paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution | ||
| CVE-2019-12748 | — | 0.00 | — | 0.00 | Jul 9, 2019 | TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. | ||
| CVE-2017-6216 | — | 0.00 | — | 0.00 | Jul 3, 2019 | novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution | ||
| CVE-2018-11317 | — | 0.00 | — | 0.00 | Jul 3, 2019 | Subrion CMS before 4.1.4 has XSS. | ||
| CVE-2019-13127 | — | 0.00 | — | 0.00 | Jul 1, 2019 | An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs… | ||
| CVE-2019-12935 | — | 0.00 | — | 0.03 | Jun 23, 2019 | Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. | ||
| CVE-2018-16514 | — | 0.00 | — | 0.00 | Jun 20, 2019 | A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted… | ||
| CVE-2019-12823 | — | 0.00 | — | 0.00 | Jun 18, 2019 | Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. | ||
| CVE-2019-10335 | 0.00 | — | 0.00 | Jun 11, 2019 | A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status… | |||
| CVE-2019-10336 | 0.00 | — | 0.00 | Jun 11, 2019 | A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this… | |||
| CVE-2019-12732 | — | 0.00 | — | 0.00 | Jun 6, 2019 | The Chartkick gem through 3.1.0 for Ruby allows XSS. | ||
| CVE-2019-12741 | — | 0.00 | — | 0.00 | Jun 5, 2019 | XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via… | ||
| CVE-2019-12308 | — | 0.00 | — | 0.03 | Jun 3, 2019 | An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database,… | ||
| CVE-2019-10047 | — | 0.00 | — | 0.00 | May 31, 2019 | A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML file containing JavaScript code and afterwards a file… | ||
| CVE-2019-10325 | 0.00 | — | 0.00 | May 31, 2019 | A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages. | |||
| CVE-2019-0221 | — | 0.00 | — | 0.14 | May 28, 2019 | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be… |
- CVE-2019-10346Jul 11, 2019risk 0.00cvss —epss 0.00
A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
- CVE-2019-10349Jul 11, 2019risk 0.00cvss —epss 0.01
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
- CVE-2019-13506Jul 11, 2019risk 0.00cvss —epss 0.01
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
- CVE-2019-12471Jul 10, 2019risk 0.00cvss —epss 0.00
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
- CVE-2017-6217Jul 10, 2019risk 0.00cvss —epss 0.00
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
- CVE-2019-12748Jul 9, 2019risk 0.00cvss —epss 0.00
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
- CVE-2017-6216Jul 3, 2019risk 0.00cvss —epss 0.00
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
- CVE-2018-11317Jul 3, 2019risk 0.00cvss —epss 0.00
Subrion CMS before 4.1.4 has XSS.
- CVE-2019-13127Jul 1, 2019risk 0.00cvss —epss 0.00
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs…
- CVE-2019-12935Jun 23, 2019risk 0.00cvss —epss 0.03
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
- CVE-2018-16514Jun 20, 2019risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted…
- CVE-2019-12823Jun 18, 2019risk 0.00cvss —epss 0.00
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
- CVE-2019-10335Jun 11, 2019risk 0.00cvss —epss 0.00
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status…
- CVE-2019-10336Jun 11, 2019risk 0.00cvss —epss 0.00
A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this…
- CVE-2019-12732Jun 6, 2019risk 0.00cvss —epss 0.00
The Chartkick gem through 3.1.0 for Ruby allows XSS.
- CVE-2019-12741Jun 5, 2019risk 0.00cvss —epss 0.00
XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via…
- CVE-2019-12308Jun 3, 2019risk 0.00cvss —epss 0.03
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database,…
- CVE-2019-10047May 31, 2019risk 0.00cvss —epss 0.00
A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML file containing JavaScript code and afterwards a file…
- CVE-2019-10325May 31, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
- CVE-2019-0221May 28, 2019risk 0.00cvss —epss 0.14
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be…