VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 916 of 1,159
  • CVE-2019-11876May 24, 2019
    risk 0.00cvss epss 0.00

    In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing…

  • CVE-2019-12313May 24, 2019
    risk 0.00cvss epss 0.00

    XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.

  • CVE-2019-10078May 20, 2019
    risk 0.00cvss epss 0.03

    A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

  • CVE-2019-10077May 20, 2019
    risk 0.00cvss epss 0.03

    A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

  • CVE-2019-10076May 20, 2019
    risk 0.00cvss epss 0.03

    A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

  • CVE-2019-10909May 16, 2019
    risk 0.00cvss epss 0.00

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

  • CVE-2019-10913May 16, 2019
    risk 0.00cvss epss 0.00

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is…

  • CVE-2019-12139May 16, 2019
    risk 0.00cvss epss 0.00

    An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezplatform-page-builder 1.1.x before 1.1.5 and 1.2.x before 1.2.4.

  • CVE-2018-19048May 13, 2019
    risk 0.00cvss epss 0.00

    Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.

  • CVE-2019-12043May 13, 2019
    risk 0.00cvss epss 0.00

    In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.

  • CVE-2019-11818May 8, 2019
    risk 0.00cvss epss 0.00

    Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be…

  • CVE-2018-13983May 6, 2019
    risk 0.00cvss epss 0.00

    ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

  • CVE-2018-8035May 1, 2019
    risk 0.00cvss epss 0.04

    This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user…

  • CVE-2019-0213Apr 30, 2019
    risk 0.00cvss epss 0.01

    In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the…

  • CVE-2015-9286Apr 30, 2019
    risk 0.00cvss epss 0.00

    Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

  • CVE-2018-1328Apr 23, 2019
    risk 0.00cvss epss 0.01

    Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

  • CVE-2019-11358Apr 19, 2019
    risk 0.00cvss epss 0.01

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

  • CVE-2019-1003050Apr 10, 2019
    risk 0.00cvss epss 0.00

    The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

  • CVE-2019-0216Apr 10, 2019
    risk 0.00cvss epss 0.01

    A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

  • CVE-2019-11004Apr 8, 2019
    risk 0.00cvss epss 0.00

    In Materialize through 1.0.0, XSS is possible via the Toast feature.