CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 925 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12290 | — | 0.00 | — | 0.00 | Jun 13, 2018 | The Yii2-StateMachine extension v2.x.x for Yii2 has XSS. | ||
| CVE-2018-12099 | — | 0.00 | — | 0.01 | Jun 11, 2018 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. | ||
| CVE-2018-3716 | — | 0.00 | — | 0.00 | Jun 7, 2018 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | ||
| CVE-2018-3717 | — | 0.00 | — | 0.00 | Jun 7, 2018 | connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. | ||
| CVE-2018-3726 | 0.00 | — | 0.00 | Jun 7, 2018 | crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | |||
| CVE-2018-3735 | — | 0.00 | — | 0.00 | Jun 7, 2018 | bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template | ||
| CVE-2018-1000202 | — | 0.00 | — | 0.00 | Jun 5, 2018 | A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user… | ||
| CVE-2017-18286 | — | 0.00 | — | 0.00 | Jun 5, 2018 | nZEDb v0.7.3.3 has XSS in the 404 error page. | ||
| CVE-2017-0931 | — | 0.00 | — | 0.00 | Jun 4, 2018 | html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values. | ||
| CVE-2017-16022 | 0.00 | — | 0.00 | Jun 4, 2018 | Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that… | |||
| CVE-2017-16019 | — | 0.00 | — | 0.00 | Jun 4, 2018 | GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on… | ||
| CVE-2017-16018 | — | 0.00 | — | 0.00 | Jun 4, 2018 | Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers. | ||
| CVE-2017-16017 | — | 0.00 | — | 0.00 | Jun 4, 2018 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | ||
| CVE-2017-16016 | — | 0.00 | — | 0.00 | Jun 4, 2018 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. | ||
| CVE-2017-16009 | — | 0.00 | — | 0.00 | Jun 4, 2018 | ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid. | ||
| CVE-2017-16008 | — | 0.00 | — | 0.00 | Jun 4, 2018 | i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next… | ||
| CVE-2017-16006 | — | 0.00 | — | 0.00 | Jun 4, 2018 | Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript. | ||
| CVE-2018-3755 | — | 0.00 | — | 0.00 | Jun 1, 2018 | XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with element used in directory name. | ||
| CVE-2018-11651 | — | 0.00 | — | 0.00 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | ||
| CVE-2018-11650 | — | 0.00 | — | 0.00 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. |
- CVE-2018-12290Jun 13, 2018risk 0.00cvss —epss 0.00
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
- CVE-2018-12099Jun 11, 2018risk 0.00cvss —epss 0.01
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
- CVE-2018-3716Jun 7, 2018risk 0.00cvss —epss 0.00
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
- CVE-2018-3717Jun 7, 2018risk 0.00cvss —epss 0.00
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
- CVE-2018-3726Jun 7, 2018risk 0.00cvss —epss 0.00
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
- CVE-2018-3735Jun 7, 2018risk 0.00cvss —epss 0.00
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
- CVE-2018-1000202Jun 5, 2018risk 0.00cvss —epss 0.00
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user…
- CVE-2017-18286Jun 5, 2018risk 0.00cvss —epss 0.00
nZEDb v0.7.3.3 has XSS in the 404 error page.
- CVE-2017-0931Jun 4, 2018risk 0.00cvss —epss 0.00
html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values.
- CVE-2017-16022Jun 4, 2018risk 0.00cvss —epss 0.00
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that…
- CVE-2017-16019Jun 4, 2018risk 0.00cvss —epss 0.00
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on…
- CVE-2017-16018Jun 4, 2018risk 0.00cvss —epss 0.00
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers.
- CVE-2017-16017Jun 4, 2018risk 0.00cvss —epss 0.00
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.
- CVE-2017-16016Jun 4, 2018risk 0.00cvss —epss 0.00
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.
- CVE-2017-16009Jun 4, 2018risk 0.00cvss —epss 0.00
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
- CVE-2017-16008Jun 4, 2018risk 0.00cvss —epss 0.00
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next…
- CVE-2017-16006Jun 4, 2018risk 0.00cvss —epss 0.00
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.
- CVE-2018-3755Jun 1, 2018risk 0.00cvss —epss 0.00
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with element used in directory name.
- CVE-2018-11651Jun 1, 2018risk 0.00cvss —epss 0.00
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
- CVE-2018-11650Jun 1, 2018risk 0.00cvss —epss 0.00
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.