VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 919 of 1,159
  • CVE-2019-7173Jan 29, 2019
    risk 0.00cvss epss 0.00

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.

  • CVE-2019-6804Jan 25, 2019
    risk 0.00cvss epss 0.09

    An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.

  • CVE-2019-6802Jan 25, 2019
    risk 0.00cvss epss 0.01

    CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

  • CVE-2017-17836Jan 23, 2019
    risk 0.00cvss epss 0.00

    In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a machine unlocked can exfiltrate all…

  • CVE-2018-16887Jan 13, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can…

  • CVE-2017-1002152Jan 10, 2019
    risk 0.00cvss epss 0.00

    Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

  • CVE-2018-20682Jan 9, 2019
    risk 0.00cvss epss 0.00

    Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

  • CVE-2018-1000413Jan 9, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.

  • CVE-2018-1000407Jan 9, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.

  • CVE-2018-1000415Jan 9, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterValue.jelly,…

  • CVE-2018-1000416Jan 9, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.

  • CVE-2018-1000426Jan 9, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly…

  • CVE-2018-20676Jan 9, 2019
    risk 0.00cvss epss 0.06

    In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

  • CVE-2016-10735Jan 9, 2019
    risk 0.00cvss epss 0.05

    In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

  • CVE-2018-20677Jan 9, 2019
    risk 0.00cvss epss 0.10

    In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

  • CVE-2018-19993Jan 3, 2019
    risk 0.00cvss epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

  • CVE-2018-19992Jan 3, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

  • CVE-2018-19995Jan 3, 2019
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

  • CVE-2018-20663Jan 3, 2019
    risk 0.00cvss epss 0.00

    The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.

  • CVE-2018-6333Dec 31, 2018
    risk 0.00cvss epss 0.01

    The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code…