CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 921 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19289 | — | 0.00 | — | 0.00 | Nov 15, 2018 | An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file. | ||
| CVE-2018-17960 | — | 0.00 | — | 0.02 | Nov 14, 2018 | CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste. | ||
| CVE-2018-19280 | — | 0.00 | — | 0.00 | Nov 14, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro. | ||
| CVE-2018-16471 | 0.00 | — | 0.01 | Nov 13, 2018 | There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value… | |||
| CVE-2018-14655 | 0.00 | — | 0.00 | Nov 13, 2018 | A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login. | |||
| CVE-2018-19056 | — | 0.00 | — | 0.00 | Nov 7, 2018 | pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. | ||
| CVE-2018-19057 | — | 0.00 | — | 0.00 | Nov 7, 2018 | SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element. | ||
| CVE-2018-16474 | — | 0.00 | — | 0.00 | Nov 6, 2018 | A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. | ||
| CVE-2018-18943 | — | 0.00 | — | 0.00 | Nov 5, 2018 | An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI. | ||
| CVE-2018-16468 | — | 0.00 | — | 0.00 | Oct 30, 2018 | In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. | ||
| CVE-2018-17783 | — | 0.00 | — | 0.00 | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name. | ||
| CVE-2018-17782 | — | 0.00 | — | 0.00 | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name. | ||
| CVE-2018-18478 | — | 0.00 | — | 0.00 | Oct 18, 2018 | Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,… | ||
| CVE-2018-18307 | — | 0.00 | — | 0.00 | Oct 16, 2018 | A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route.… | ||
| CVE-2017-5934 | — | 0.00 | — | 0.01 | Oct 15, 2018 | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2018-18260 | — | 0.00 | — | 0.00 | Oct 15, 2018 | In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any… | ||
| CVE-2018-18282 | — | 0.00 | — | 0.00 | Oct 12, 2018 | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. | ||
| CVE-2018-8006 | 0.00 | — | 0.79 | Oct 10, 2018 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter. | |||
| CVE-2018-17876 | — | 0.00 | — | 0.00 | Oct 4, 2018 | A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product. | ||
| CVE-2018-15563 | — | 0.00 | — | 0.00 | Oct 2, 2018 | _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter. |
- CVE-2018-19289Nov 15, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
- CVE-2018-17960Nov 14, 2018risk 0.00cvss —epss 0.02
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
- CVE-2018-19280Nov 14, 2018risk 0.00cvss —epss 0.00
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
- CVE-2018-16471Nov 13, 2018risk 0.00cvss —epss 0.01
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value…
- CVE-2018-14655Nov 13, 2018risk 0.00cvss —epss 0.00
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
- CVE-2018-19056Nov 7, 2018risk 0.00cvss —epss 0.00
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
- CVE-2018-19057Nov 7, 2018risk 0.00cvss —epss 0.00
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
- CVE-2018-16474Nov 6, 2018risk 0.00cvss —epss 0.00
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
- CVE-2018-18943Nov 5, 2018risk 0.00cvss —epss 0.00
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.
- CVE-2018-16468Oct 30, 2018risk 0.00cvss —epss 0.00
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
- CVE-2018-17783Oct 30, 2018risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
- CVE-2018-17782Oct 30, 2018risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
- CVE-2018-18478Oct 18, 2018risk 0.00cvss —epss 0.00
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…
- CVE-2018-18307Oct 16, 2018risk 0.00cvss —epss 0.00
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route.…
- CVE-2017-5934Oct 15, 2018risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-18260Oct 15, 2018risk 0.00cvss —epss 0.00
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any…
- CVE-2018-18282Oct 12, 2018risk 0.00cvss —epss 0.00
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
- CVE-2018-8006Oct 10, 2018risk 0.00cvss —epss 0.79
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
- CVE-2018-17876Oct 4, 2018risk 0.00cvss —epss 0.00
A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.
- CVE-2018-15563Oct 2, 2018risk 0.00cvss —epss 0.00
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.