VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 92 of 2,331
  • CVE-2024-33338HigApr 29, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.

  • CVE-2024-32391HigApr 19, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-30920HigApr 18, 2024
    risk 0.48cvss 7.4epss 0.01

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.

  • CVE-2024-29154HigMar 18, 2024
    risk 0.48cvss 7.4epss 0.00

    danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.

  • CVE-2024-1529HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially…

  • CVE-2024-1528HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted…

  • CVE-2020-36769HigDec 23, 2023
    risk 0.48cvss 7.4epss 0.00

    The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2020-18336HigOct 10, 2023
    risk 0.48cvss 7.4epss 0.01

    Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function.

  • CVE-2023-3971HigOct 4, 2023
    risk 0.48cvss 7.3epss 0.01

    An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

  • CVE-2023-3550HigSep 25, 2023
    risk 0.48cvss 7.3epss 0.01

    Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the…

  • CVE-2023-4136HigAug 3, 2023
    risk 0.48cvss 7.4epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

  • CVE-2021-42080HigJul 10, 2023
    risk 0.48cvss 7.4epss 0.01

    An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)>

  • CVE-2023-35157HigJun 23, 2023
    risk 0.48cvss 8.4epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited only if the attacker knows…

  • CVE-2023-33130HigJun 14, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2022-43760HigJun 1, 2023
    risk 0.48cvss 8.4epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive…

  • CVE-2023-25599HigMay 24, 2023
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful…

  • CVE-2023-2757HigMay 18, 2023
    risk 0.48cvss 7.4epss 0.00

    The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and…

  • CVE-2023-30838HigApr 25, 2023
    risk 0.48cvss 8.5epss 0.01

    PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes`…

  • CVE-2023-28341MedApr 11, 2023
    risk 0.48cvss 6.1epss 0.99

    Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

  • CVE-2023-0594HigMar 1, 2023
    risk 0.48cvss 7.3epss 0.09

    Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attributes/resources were not…