VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 924 of 1,159
  • CVE-2018-14041Jul 13, 2018
    risk 0.00cvss epss 0.08

    In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

  • CVE-2018-13339Jul 5, 2018
    risk 0.00cvss epss 0.00

    Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.

  • CVE-2018-3769Jul 5, 2018
    risk 0.00cvss epss 0.00

    ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.

  • CVE-2018-3748Jul 3, 2018
    risk 0.00cvss epss 0.00

    There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in element) allows to execute JavaScript code against any user who opens a directory…

  • CVE-2018-3747Jul 3, 2018
    risk 0.00cvss epss 0.00

    The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.

  • CVE-2018-0499Jul 2, 2018
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().

  • CVE-2018-13003Jun 29, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.

  • CVE-2018-12973Jun 29, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.

  • CVE-2018-1000604Jun 26, 2018
    risk 0.00cvss epss 0.00

    A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when…

  • CVE-2018-1000516Jun 26, 2018
    risk 0.00cvss epss 0.01

    The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In…

  • CVE-2018-1000529Jun 26, 2018
    risk 0.00cvss epss 0.00

    Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.

  • CVE-2018-1000534Jun 26, 2018
    risk 0.00cvss epss 0.00

    Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here…

  • CVE-2018-1000559Jun 26, 2018
    risk 0.00cvss epss 0.01

    qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This…

  • CVE-2018-0570Jun 26, 2018
    risk 0.00cvss epss 0.00

    Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-0574Jun 26, 2018
    risk 0.00cvss epss 0.00

    Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-12581Jun 21, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

  • CVE-2018-12104Jun 17, 2018
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.

  • CVE-2018-11647Jun 17, 2018
    risk 0.00cvss epss 0.00

    index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.

  • CVE-2018-12432Jun 14, 2018
    risk 0.00cvss epss 0.00

    JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.

  • CVE-2018-11688Jun 13, 2018
    risk 0.00cvss epss 0.03

    Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the…