CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 919 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7173 | 0.00 | — | 0.00 | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4. | |||
| CVE-2019-6804 | 0.00 | — | 0.09 | Jan 25, 2019 | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp. | |||
| CVE-2019-6802 | 0.00 | — | 0.01 | Jan 25, 2019 | CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. | |||
| CVE-2017-17836 | 0.00 | — | 0.00 | Jan 23, 2019 | In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can exfiltrate all… | |||
| CVE-2018-16887 | — | 0.00 | — | 0.00 | Jan 13, 2019 | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can… | ||
| CVE-2017-1002152 | — | 0.00 | — | 0.00 | Jan 10, 2019 | Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. | ||
| CVE-2018-20682 | 0.00 | — | 0.00 | Jan 9, 2019 | Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section). | |||
| CVE-2018-1000413 | 0.00 | — | 0.00 | Jan 9, 2019 | A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins. | |||
| CVE-2018-1000407 | 0.00 | — | 0.00 | Jan 9, 2019 | A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins. | |||
| CVE-2018-1000415 | 0.00 | — | 0.00 | Jan 9, 2019 | A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterValue.jelly,… | |||
| CVE-2018-1000416 | 0.00 | — | 0.00 | Jan 9, 2019 | A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access. | |||
| CVE-2018-1000426 | 0.00 | — | 0.00 | Jan 9, 2019 | A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly… | |||
| CVE-2018-20676 | 0.00 | — | 0.06 | Jan 9, 2019 | In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. | |||
| CVE-2016-10735 | 0.00 | — | 0.05 | Jan 9, 2019 | In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. | |||
| CVE-2018-20677 | 0.00 | — | 0.10 | Jan 9, 2019 | In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. | |||
| CVE-2018-19993 | 0.00 | — | 0.00 | Jan 3, 2019 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | |||
| CVE-2018-19992 | 0.00 | — | 0.00 | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php. | |||
| CVE-2018-19995 | 0.00 | — | 0.00 | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php. | |||
| CVE-2018-20663 | 0.00 | — | 0.00 | Jan 3, 2019 | The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field. | |||
| CVE-2018-6333 | 0.00 | — | 0.01 | Dec 31, 2018 | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code… |
- CVE-2019-7173Jan 29, 2019risk 0.00cvss —epss 0.00
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.
- CVE-2019-6804Jan 25, 2019risk 0.00cvss —epss 0.09
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.
- CVE-2019-6802Jan 25, 2019risk 0.00cvss —epss 0.01
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
- CVE-2017-17836Jan 23, 2019risk 0.00cvss —epss 0.00
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can exfiltrate all…
- CVE-2018-16887Jan 13, 2019risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can…
- CVE-2017-1002152Jan 10, 2019risk 0.00cvss —epss 0.00
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
- CVE-2018-20682Jan 9, 2019risk 0.00cvss —epss 0.00
Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).
- CVE-2018-1000413Jan 9, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
- CVE-2018-1000407Jan 9, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
- CVE-2018-1000415Jan 9, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterValue.jelly,…
- CVE-2018-1000416Jan 9, 2019risk 0.00cvss —epss 0.00
A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.
- CVE-2018-1000426Jan 9, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly…
- CVE-2018-20676Jan 9, 2019risk 0.00cvss —epss 0.06
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
- CVE-2016-10735Jan 9, 2019risk 0.00cvss —epss 0.05
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
- CVE-2018-20677Jan 9, 2019risk 0.00cvss —epss 0.10
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
- CVE-2018-19993Jan 3, 2019risk 0.00cvss —epss 0.00
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.
- CVE-2018-19992Jan 3, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.
- CVE-2018-19995Jan 3, 2019risk 0.00cvss —epss 0.00
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.
- CVE-2018-20663Jan 3, 2019risk 0.00cvss —epss 0.00
The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.
- CVE-2018-6333Dec 31, 2018risk 0.00cvss —epss 0.01
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code…