VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 920 of 1,159
  • CVE-2018-20594Dec 30, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.

  • CVE-2018-20583Dec 30, 2018
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as…

  • CVE-2018-16638Dec 28, 2018
    risk 0.00cvss epss 0.00

    Evolution CMS 1.4.x allows XSS via the manager/ search parameter.

  • CVE-2018-16637Dec 28, 2018
    risk 0.00cvss epss 0.00

    Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.

  • CVE-2018-16630Dec 28, 2018
    risk 0.00cvss epss 0.00

    Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.

  • CVE-2018-1000855Dec 20, 2018
    risk 0.00cvss epss 0.00

    easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal cookies, depending on the cookie settings.. This attack appear to be…

  • CVE-2018-1000816Dec 20, 2018
    risk 0.00cvss epss 0.00

    Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the…

  • CVE-2018-1000826Dec 20, 2018
    risk 0.00cvss epss 0.00

    Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.

  • CVE-2018-1000842Dec 20, 2018
    risk 0.00cvss epss 0.00

    FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 that can result in Javascript execution. This attack appear to be exploitable via…

  • CVE-2018-20302Dec 20, 2018
    risk 0.00cvss epss 0.00

    An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.

  • CVE-2018-17193Dec 19, 2018
    risk 0.00cvss epss 0.02

    The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release.…

  • CVE-2017-18352Dec 17, 2018
    risk 0.00cvss epss 0.00

    Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.

  • CVE-2018-19970Dec 11, 2018
    risk 0.00cvss epss 0.01

    In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

  • CVE-2018-16629Dec 4, 2018
    risk 0.00cvss epss 0.00

    panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.

  • CVE-2018-19787Dec 2, 2018
    risk 0.00cvss epss 0.01

    An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar…

  • CVE-2018-19785Dec 1, 2018
    risk 0.00cvss epss 0.00

    PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.

  • CVE-2018-17256Nov 27, 2018
    risk 0.00cvss epss 0.00

    Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing public access of a content.

  • CVE-2018-19351Nov 18, 2018
    risk 0.00cvss epss 0.00

    Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In…

  • CVE-2018-19352Nov 18, 2018
    risk 0.00cvss epss 0.00

    Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.

  • CVE-2018-19311Nov 16, 2018
    risk 0.00cvss epss 0.00

    Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.