VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 921 of 1,159
  • CVE-2018-19289Nov 15, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.

  • CVE-2018-17960Nov 14, 2018
    risk 0.00cvss epss 0.02

    CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.

  • CVE-2018-19280Nov 14, 2018
    risk 0.00cvss epss 0.00

    Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

  • CVE-2018-16471Nov 13, 2018
    risk 0.00cvss epss 0.01

    There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value…

  • CVE-2018-14655Nov 13, 2018
    risk 0.00cvss epss 0.00

    A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.

  • CVE-2018-19056Nov 7, 2018
    risk 0.00cvss epss 0.00

    pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.

  • CVE-2018-19057Nov 7, 2018
    risk 0.00cvss epss 0.00

    SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.

  • CVE-2018-16474Nov 6, 2018
    risk 0.00cvss epss 0.00

    A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.

  • CVE-2018-18943Nov 5, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.

  • CVE-2018-16468Oct 30, 2018
    risk 0.00cvss epss 0.00

    In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

  • CVE-2018-17783Oct 30, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.

  • CVE-2018-17782Oct 30, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.

  • CVE-2018-18478Oct 18, 2018
    risk 0.00cvss epss 0.00

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…

  • CVE-2018-18307Oct 16, 2018
    risk 0.00cvss epss 0.00

    A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route.…

  • CVE-2017-5934Oct 15, 2018
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-18260Oct 15, 2018
    risk 0.00cvss epss 0.00

    In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any…

  • CVE-2018-18282Oct 12, 2018
    risk 0.00cvss epss 0.00

    Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

  • CVE-2018-8006Oct 10, 2018
    risk 0.00cvss epss 0.79

    An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

  • CVE-2018-17876Oct 4, 2018
    risk 0.00cvss epss 0.00

    A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.

  • CVE-2018-15563Oct 2, 2018
    risk 0.00cvss epss 0.00

    _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.