CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 923 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-1000640 | — | 0.00 | — | 0.00 | Aug 20, 2018 | OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack… | ||
| CVE-2017-12614 | 0.00 | — | 0.02 | Aug 6, 2018 | It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is… | |||
| CVE-2018-13055 | — | 0.00 | — | 0.00 | Aug 3, 2018 | A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. | ||
| CVE-2018-14504 | — | 0.00 | — | 0.00 | Aug 3, 2018 | An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar"… | ||
| CVE-2017-6215 | — | 0.00 | — | 0.00 | Aug 2, 2018 | paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution. | ||
| CVE-2017-6213 | — | 0.00 | — | 0.00 | Aug 2, 2018 | paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution. | ||
| CVE-2018-8032 | 0.00 | — | 0.02 | Aug 2, 2018 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |||
| CVE-2018-14840 | — | 0.00 | — | 0.03 | Aug 2, 2018 | uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads). | ||
| CVE-2018-14835 | — | 0.00 | — | 0.00 | Aug 2, 2018 | Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas. | ||
| CVE-2018-1999029 | — | 0.00 | — | 0.00 | Aug 1, 2018 | A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's… | ||
| CVE-2018-3773 | — | 0.00 | — | 0.00 | Jul 30, 2018 | There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2. | ||
| CVE-2018-8031 | — | 0.00 | — | 0.02 | Jul 23, 2018 | The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles do not ship with this… | ||
| CVE-2018-1999005 | — | 0.00 | — | 0.00 | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser… | ||
| CVE-2018-1999007 | — | 0.00 | — | 0.00 | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would… | ||
| CVE-2018-1999024 | — | 0.00 | — | 0.00 | Jul 23, 2018 | MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via The victim must view a page where… | ||
| CVE-2018-1999021 | — | 0.00 | — | 0.00 | Jul 23, 2018 | Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile… | ||
| CVE-2018-3771 | — | 0.00 | — | 0.00 | Jul 20, 2018 | An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser. | ||
| CVE-2018-14380 | — | 0.00 | — | 0.00 | Jul 18, 2018 | In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts. | ||
| CVE-2018-14040 | — | 0.00 | — | 0.02 | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | ||
| CVE-2018-14041 | — | 0.00 | — | 0.08 | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. |
- CVE-2018-1000640Aug 20, 2018risk 0.00cvss —epss 0.00
OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack…
- CVE-2017-12614Aug 6, 2018risk 0.00cvss —epss 0.02
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is…
- CVE-2018-13055Aug 3, 2018risk 0.00cvss —epss 0.00
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.
- CVE-2018-14504Aug 3, 2018risk 0.00cvss —epss 0.00
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar"…
- CVE-2017-6215Aug 2, 2018risk 0.00cvss —epss 0.00
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
- CVE-2017-6213Aug 2, 2018risk 0.00cvss —epss 0.00
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
- CVE-2018-8032Aug 2, 2018risk 0.00cvss —epss 0.02
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
- CVE-2018-14840Aug 2, 2018risk 0.00cvss —epss 0.03
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).
- CVE-2018-14835Aug 2, 2018risk 0.00cvss —epss 0.00
Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.
- CVE-2018-1999029Aug 1, 2018risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's…
- CVE-2018-3773Jul 30, 2018risk 0.00cvss —epss 0.00
There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.
- CVE-2018-8031Jul 23, 2018risk 0.00cvss —epss 0.02
The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles do not ship with this…
- CVE-2018-1999005Jul 23, 2018risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser…
- CVE-2018-1999007Jul 23, 2018risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would…
- CVE-2018-1999024Jul 23, 2018risk 0.00cvss —epss 0.00
MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via The victim must view a page where…
- CVE-2018-1999021Jul 23, 2018risk 0.00cvss —epss 0.00
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile…
- CVE-2018-3771Jul 20, 2018risk 0.00cvss —epss 0.00
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
- CVE-2018-14380Jul 18, 2018risk 0.00cvss —epss 0.00
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
- CVE-2018-14040Jul 13, 2018risk 0.00cvss —epss 0.02
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
- CVE-2018-14041Jul 13, 2018risk 0.00cvss —epss 0.08
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.