VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 923 of 1,159
  • CVE-2018-1000640Aug 20, 2018
    risk 0.00cvss epss 0.00

    OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack…

  • CVE-2017-12614Aug 6, 2018
    risk 0.00cvss epss 0.02

    It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is…

  • CVE-2018-13055Aug 3, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.

  • CVE-2018-14504Aug 3, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with a crafted name (e.g., 'foobar"…

  • CVE-2017-6215Aug 2, 2018
    risk 0.00cvss epss 0.00

    paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.

  • CVE-2017-6213Aug 2, 2018
    risk 0.00cvss epss 0.00

    paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.

  • CVE-2018-8032Aug 2, 2018
    risk 0.00cvss epss 0.02

    Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

  • CVE-2018-14840Aug 2, 2018
    risk 0.00cvss epss 0.03

    uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).

  • CVE-2018-14835Aug 2, 2018
    risk 0.00cvss epss 0.00

    Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed in multiple areas.

  • CVE-2018-1999029Aug 1, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's…

  • CVE-2018-3773Jul 30, 2018
    risk 0.00cvss epss 0.00

    There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.

  • CVE-2018-8031Jul 23, 2018
    risk 0.00cvss epss 0.02

    The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles do not ship with this…

  • CVE-2018-1999005Jul 23, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser…

  • CVE-2018-1999007Jul 23, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would…

  • CVE-2018-1999024Jul 23, 2018
    risk 0.00cvss epss 0.00

    MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via The victim must view a page where…

  • CVE-2018-1999021Jul 23, 2018
    risk 0.00cvss epss 0.00

    Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile…

  • CVE-2018-3771Jul 20, 2018
    risk 0.00cvss epss 0.00

    An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.

  • CVE-2018-14380Jul 18, 2018
    risk 0.00cvss epss 0.00

    In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.

  • CVE-2018-14040Jul 13, 2018
    risk 0.00cvss epss 0.02

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

  • CVE-2018-14041Jul 13, 2018
    risk 0.00cvss epss 0.08

    In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.