CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 922 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17574 | — | 0.00 | — | 0.00 | Sep 28, 2018 | An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. | ||
| CVE-2018-16277 | — | 0.00 | — | 0.00 | Sep 28, 2018 | The Image Import function in XWiki through 10.7 has XSS. | ||
| CVE-2018-11352 | — | 0.00 | — | 0.00 | Sep 21, 2018 | The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The… | ||
| CVE-2018-3824 | 0.00 | — | 0.00 | Sep 19, 2018 | X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to… | |||
| CVE-2018-14631 | — | 0.00 | — | 0.00 | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected… | ||
| CVE-2018-17031 | — | 0.00 | — | 0.00 | Sep 14, 2018 | In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent. | ||
| CVE-2018-1000665 | — | 0.00 | — | 0.00 | Sep 6, 2018 | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked… | ||
| CVE-2018-16459 | — | 0.00 | — | 0.00 | Sep 6, 2018 | An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser. | ||
| CVE-2018-16551 | — | 0.00 | — | 0.00 | Sep 5, 2018 | LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. | ||
| CVE-2018-16516 | — | 0.00 | — | 0.00 | Sep 5, 2018 | helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL. | ||
| CVE-2018-16407 | — | 0.00 | — | 0.00 | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. | ||
| CVE-2018-16405 | — | 0.00 | — | 0.00 | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. | ||
| CVE-2018-16406 | — | 0.00 | — | 0.00 | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. | ||
| CVE-2018-16342 | — | 0.00 | — | 0.00 | Sep 2, 2018 | ShowDoc v1.8.0 has XSS via a new page. | ||
| CVE-2018-16347 | — | 0.00 | — | 0.00 | Sep 2, 2018 | An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize. | ||
| CVE-2018-16330 | — | 0.00 | — | 0.00 | Sep 2, 2018 | Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. | ||
| CVE-2018-16327 | — | 0.00 | — | 0.00 | Sep 1, 2018 | There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration. | ||
| CVE-2018-15605 | — | 0.00 | — | 0.01 | Aug 24, 2018 | An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature. | ||
| CVE-2016-9605 | — | 0.00 | — | 0.00 | Aug 22, 2018 | A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation. | ||
| CVE-2018-1000225 | — | 0.00 | — | 0.00 | Aug 20, 2018 | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin..… |
- CVE-2018-17574Sep 28, 2018risk 0.00cvss —epss 0.00
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
- CVE-2018-16277Sep 28, 2018risk 0.00cvss —epss 0.00
The Image Import function in XWiki through 10.7 has XSS.
- CVE-2018-11352Sep 21, 2018risk 0.00cvss —epss 0.00
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The…
- CVE-2018-3824Sep 19, 2018risk 0.00cvss —epss 0.00
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to…
- CVE-2018-14631Sep 17, 2018risk 0.00cvss —epss 0.00
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…
- CVE-2018-17031Sep 14, 2018risk 0.00cvss —epss 0.00
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
- CVE-2018-1000665Sep 6, 2018risk 0.00cvss —epss 0.00
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked…
- CVE-2018-16459Sep 6, 2018risk 0.00cvss —epss 0.00
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
- CVE-2018-16551Sep 5, 2018risk 0.00cvss —epss 0.00
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
- CVE-2018-16516Sep 5, 2018risk 0.00cvss —epss 0.00
helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
- CVE-2018-16407Sep 3, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.
- CVE-2018-16405Sep 3, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
- CVE-2018-16406Sep 3, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.
- CVE-2018-16342Sep 2, 2018risk 0.00cvss —epss 0.00
ShowDoc v1.8.0 has XSS via a new page.
- CVE-2018-16347Sep 2, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
- CVE-2018-16330Sep 2, 2018risk 0.00cvss —epss 0.00
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
- CVE-2018-16327Sep 1, 2018risk 0.00cvss —epss 0.00
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
- CVE-2018-15605Aug 24, 2018risk 0.00cvss —epss 0.01
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.
- CVE-2016-9605Aug 22, 2018risk 0.00cvss —epss 0.00
A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnerability, leading the arbitrary file reading. The flaw is triggered by navigating to a vulnerable URL via cobbler-web on a default installation.
- CVE-2018-1000225Aug 20, 2018risk 0.00cvss —epss 0.00
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin..…