CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 920 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20594 | 0.00 | — | 0.00 | Dec 30, 2018 | An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java. | |||
| CVE-2018-20583 | 0.00 | — | 0.00 | Dec 30, 2018 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as… | |||
| CVE-2018-16638 | 0.00 | — | 0.00 | Dec 28, 2018 | Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |||
| CVE-2018-16637 | 0.00 | — | 0.00 | Dec 28, 2018 | Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |||
| CVE-2018-16630 | 0.00 | — | 0.00 | Dec 28, 2018 | Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file. | |||
| CVE-2018-1000855 | — | 0.00 | — | 0.00 | Dec 20, 2018 | easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal cookies, depending on the cookie settings.. This attack appear to be… | ||
| CVE-2018-1000816 | — | 0.00 | — | 0.00 | Dec 20, 2018 | Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the… | ||
| CVE-2018-1000826 | — | 0.00 | — | 0.00 | Dec 20, 2018 | Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code. | ||
| CVE-2018-1000842 | — | 0.00 | — | 0.00 | Dec 20, 2018 | FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 that can result in Javascript execution. This attack appear to be exploitable via… | ||
| CVE-2018-20302 | — | 0.00 | — | 0.00 | Dec 20, 2018 | An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter. | ||
| CVE-2018-17193 | 0.00 | — | 0.02 | Dec 19, 2018 | The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release.… | |||
| CVE-2017-18352 | — | 0.00 | — | 0.00 | Dec 17, 2018 | Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. | ||
| CVE-2018-19970 | — | 0.00 | — | 0.01 | Dec 11, 2018 | In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. | ||
| CVE-2018-16629 | — | 0.00 | — | 0.00 | Dec 4, 2018 | panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | ||
| CVE-2018-19787 | — | 0.00 | — | 0.01 | Dec 2, 2018 | An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar… | ||
| CVE-2018-19785 | — | 0.00 | — | 0.00 | Dec 1, 2018 | PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php. | ||
| CVE-2018-17256 | — | 0.00 | — | 0.00 | Nov 27, 2018 | Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing public access of a content. | ||
| CVE-2018-19351 | — | 0.00 | — | 0.00 | Nov 18, 2018 | Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In… | ||
| CVE-2018-19352 | — | 0.00 | — | 0.00 | Nov 18, 2018 | Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. | ||
| CVE-2018-19311 | — | 0.00 | — | 0.00 | Nov 16, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen. |
- CVE-2018-20594Dec 30, 2018risk 0.00cvss —epss 0.00
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.
- CVE-2018-20583Dec 30, 2018risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as…
- CVE-2018-16638Dec 28, 2018risk 0.00cvss —epss 0.00
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
- CVE-2018-16637Dec 28, 2018risk 0.00cvss —epss 0.00
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
- CVE-2018-16630Dec 28, 2018risk 0.00cvss —epss 0.00
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
- CVE-2018-1000855Dec 20, 2018risk 0.00cvss —epss 0.00
easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal cookies, depending on the cookie settings.. This attack appear to be…
- CVE-2018-1000816Dec 20, 2018risk 0.00cvss —epss 0.00
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the…
- CVE-2018-1000826Dec 20, 2018risk 0.00cvss —epss 0.00
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.
- CVE-2018-1000842Dec 20, 2018risk 0.00cvss —epss 0.00
FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 that can result in Javascript execution. This attack appear to be exploitable via…
- CVE-2018-20302Dec 20, 2018risk 0.00cvss —epss 0.00
An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.
- CVE-2018-17193Dec 19, 2018risk 0.00cvss —epss 0.02
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release.…
- CVE-2017-18352Dec 17, 2018risk 0.00cvss —epss 0.00
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
- CVE-2018-19970Dec 11, 2018risk 0.00cvss —epss 0.01
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
- CVE-2018-16629Dec 4, 2018risk 0.00cvss —epss 0.00
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
- CVE-2018-19787Dec 2, 2018risk 0.00cvss —epss 0.01
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar…
- CVE-2018-19785Dec 1, 2018risk 0.00cvss —epss 0.00
PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.
- CVE-2018-17256Nov 27, 2018risk 0.00cvss —epss 0.00
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing public access of a content.
- CVE-2018-19351Nov 18, 2018risk 0.00cvss —epss 0.00
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In…
- CVE-2018-19352Nov 18, 2018risk 0.00cvss —epss 0.00
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
- CVE-2018-19311Nov 16, 2018risk 0.00cvss —epss 0.00
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.