CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 924 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14041 | — | 0.00 | — | 0.08 | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. | ||
| CVE-2018-13339 | — | 0.00 | — | 0.00 | Jul 5, 2018 | Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035. | ||
| CVE-2018-3769 | — | 0.00 | — | 0.00 | Jul 5, 2018 | ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter. | ||
| CVE-2018-3748 | — | 0.00 | — | 0.00 | Jul 3, 2018 | There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in element) allows to execute JavaScript code against any user who opens a directory… | ||
| CVE-2018-3747 | — | 0.00 | — | 0.00 | Jul 3, 2018 | The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript. | ||
| CVE-2018-0499 | — | 0.00 | — | 0.00 | Jul 2, 2018 | A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). | ||
| CVE-2018-13003 | — | 0.00 | — | 0.00 | Jun 29, 2018 | An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI. | ||
| CVE-2018-12973 | — | 0.00 | — | 0.00 | Jun 29, 2018 | An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI. | ||
| CVE-2018-1000604 | — | 0.00 | — | 0.00 | Jun 26, 2018 | A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when… | ||
| CVE-2018-1000516 | — | 0.00 | — | 0.01 | Jun 26, 2018 | The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In… | ||
| CVE-2018-1000529 | — | 0.00 | — | 0.00 | Jun 26, 2018 | Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8. | ||
| CVE-2018-1000534 | — | 0.00 | — | 0.00 | Jun 26, 2018 | Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here… | ||
| CVE-2018-1000559 | — | 0.00 | — | 0.01 | Jun 26, 2018 | qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This… | ||
| CVE-2018-0570 | 0.00 | — | 0.00 | Jun 26, 2018 | Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2018-0574 | 0.00 | — | 0.00 | Jun 26, 2018 | Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2018-12581 | — | 0.00 | — | 0.00 | Jun 21, 2018 | An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature. | ||
| CVE-2018-12104 | — | 0.00 | — | 0.00 | Jun 17, 2018 | Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI. | ||
| CVE-2018-11647 | — | 0.00 | — | 0.00 | Jun 17, 2018 | index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL. | ||
| CVE-2018-12432 | — | 0.00 | — | 0.00 | Jun 14, 2018 | JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI. | ||
| CVE-2018-11688 | — | 0.00 | — | 0.03 | Jun 13, 2018 | Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the… |
- CVE-2018-14041Jul 13, 2018risk 0.00cvss —epss 0.08
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
- CVE-2018-13339Jul 5, 2018risk 0.00cvss —epss 0.00
Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.
- CVE-2018-3769Jul 5, 2018risk 0.00cvss —epss 0.00
ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.
- CVE-2018-3748Jul 3, 2018risk 0.00cvss —epss 0.00
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in element) allows to execute JavaScript code against any user who opens a directory…
- CVE-2018-3747Jul 3, 2018risk 0.00cvss —epss 0.00
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
- CVE-2018-0499Jul 2, 2018risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
- CVE-2018-13003Jun 29, 2018risk 0.00cvss —epss 0.00
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.
- CVE-2018-12973Jun 29, 2018risk 0.00cvss —epss 0.00
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.
- CVE-2018-1000604Jun 26, 2018risk 0.00cvss —epss 0.00
A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when…
- CVE-2018-1000516Jun 26, 2018risk 0.00cvss —epss 0.01
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In…
- CVE-2018-1000529Jun 26, 2018risk 0.00cvss —epss 0.00
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
- CVE-2018-1000534Jun 26, 2018risk 0.00cvss —epss 0.00
Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here…
- CVE-2018-1000559Jun 26, 2018risk 0.00cvss —epss 0.01
qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This…
- CVE-2018-0570Jun 26, 2018risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-0574Jun 26, 2018risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-12581Jun 21, 2018risk 0.00cvss —epss 0.00
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.
- CVE-2018-12104Jun 17, 2018risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.
- CVE-2018-11647Jun 17, 2018risk 0.00cvss —epss 0.00
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
- CVE-2018-12432Jun 14, 2018risk 0.00cvss —epss 0.00
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
- CVE-2018-11688Jun 13, 2018risk 0.00cvss —epss 0.03
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the…