VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 922 of 1,159
  • CVE-2018-17574Sep 28, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.

  • CVE-2018-16277Sep 28, 2018
    risk 0.00cvss epss 0.00

    The Image Import function in XWiki through 10.7 has XSS.

  • CVE-2018-11352Sep 21, 2018
    risk 0.00cvss epss 0.00

    The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The…

  • CVE-2018-3824Sep 19, 2018
    risk 0.00cvss epss 0.00

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to…

  • CVE-2018-14631Sep 17, 2018
    risk 0.00cvss epss 0.00

    moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…

  • CVE-2018-17031Sep 14, 2018
    risk 0.00cvss epss 0.00

    In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.

  • CVE-2018-1000665Sep 6, 2018
    risk 0.00cvss epss 0.00

    Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked…

  • CVE-2018-16459Sep 6, 2018
    risk 0.00cvss epss 0.00

    An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.

  • CVE-2018-16551Sep 5, 2018
    risk 0.00cvss epss 0.00

    LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.

  • CVE-2018-16516Sep 5, 2018
    risk 0.00cvss epss 0.00

    helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.

  • CVE-2018-16407Sep 3, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.

  • CVE-2018-16405Sep 3, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.

  • CVE-2018-16406Sep 3, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.

  • CVE-2018-16342Sep 2, 2018
    risk 0.00cvss epss 0.00

    ShowDoc v1.8.0 has XSS via a new page.

  • CVE-2018-16347Sep 2, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.

  • CVE-2018-16330Sep 2, 2018
    risk 0.00cvss epss 0.00

    Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.

  • CVE-2018-16327Sep 1, 2018
    risk 0.00cvss epss 0.00

    There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.

  • CVE-2018-15605Aug 24, 2018
    risk 0.00cvss epss 0.01

    An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

  • CVE-2016-9605Aug 22, 2018
    risk 0.00cvss epss 0.00

    A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.

  • CVE-2018-1000225Aug 20, 2018
    risk 0.00cvss epss 0.00

    Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin..…