CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 928 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-7302 | — | 0.00 | — | 0.00 | Feb 21, 2018 | Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS. | ||
| CVE-2018-7261 | — | 0.00 | — | 0.00 | Feb 21, 2018 | There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields). | ||
| CVE-2018-7260 | — | 0.00 | — | 0.00 | Feb 21, 2018 | Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | ||
| CVE-2018-7274 | — | 0.00 | — | 0.00 | Feb 21, 2018 | Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name). | ||
| CVE-2018-7198 | — | 0.00 | — | 0.01 | Feb 18, 2018 | October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page. | ||
| CVE-2014-0014 | — | 0.00 | — | 0.00 | Feb 15, 2018 | Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload. | ||
| CVE-2014-0013 | — | 0.00 | — | 0.00 | Feb 15, 2018 | Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a… | ||
| CVE-2017-1000509 | — | 0.00 | — | 0.00 | Feb 9, 2018 | Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code. | ||
| CVE-2017-1000510 | — | 0.00 | — | 0.00 | Feb 9, 2018 | Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code. | ||
| CVE-2017-1000506 | — | 0.00 | — | 0.00 | Feb 9, 2018 | Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code. | ||
| CVE-2017-1000507 | — | 0.00 | — | 0.00 | Feb 9, 2018 | Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code. | ||
| CVE-2017-18121 | — | 0.00 | — | 0.00 | Feb 2, 2018 | The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser. | ||
| CVE-2018-6561 | — | 0.00 | — | 0.00 | Feb 2, 2018 | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. | ||
| CVE-2018-6464 | — | 0.00 | — | 0.00 | Jan 31, 2018 | Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1. | ||
| CVE-2017-1000389 | — | 0.00 | — | 0.00 | Jan 26, 2018 | Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected… | ||
| CVE-2017-1000404 | — | 0.00 | — | 0.00 | Jan 26, 2018 | The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs. | ||
| CVE-2017-1000386 | — | 0.00 | — | 0.00 | Jan 26, 2018 | Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference Parameter' type. This could include, for example,… | ||
| CVE-2017-1000392 | — | 0.00 | — | 0.00 | Jan 26, 2018 | Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and… | ||
| CVE-2018-6010 | — | 0.00 | — | 0.01 | Jan 22, 2018 | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and… | ||
| CVE-2018-1045 | — | 0.00 | — | 0.00 | Jan 22, 2018 | In Moodle 3.x, there is XSS via a calendar event name. |
- CVE-2018-7302Feb 21, 2018risk 0.00cvss —epss 0.00
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
- CVE-2018-7261Feb 21, 2018risk 0.00cvss —epss 0.00
There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).
- CVE-2018-7260Feb 21, 2018risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
- CVE-2018-7274Feb 21, 2018risk 0.00cvss —epss 0.00
Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name).
- CVE-2018-7198Feb 18, 2018risk 0.00cvss —epss 0.01
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
- CVE-2014-0014Feb 15, 2018risk 0.00cvss —epss 0.00
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.
- CVE-2014-0013Feb 15, 2018risk 0.00cvss —epss 0.00
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a…
- CVE-2017-1000509Feb 9, 2018risk 0.00cvss —epss 0.00
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
- CVE-2017-1000510Feb 9, 2018risk 0.00cvss —epss 0.00
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
- CVE-2017-1000506Feb 9, 2018risk 0.00cvss —epss 0.00
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
- CVE-2017-1000507Feb 9, 2018risk 0.00cvss —epss 0.00
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
- CVE-2017-18121Feb 2, 2018risk 0.00cvss —epss 0.00
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.
- CVE-2018-6561Feb 2, 2018risk 0.00cvss —epss 0.00
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
- CVE-2018-6464Jan 31, 2018risk 0.00cvss —epss 0.00
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
- CVE-2017-1000389Jan 26, 2018risk 0.00cvss —epss 0.00
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected…
- CVE-2017-1000404Jan 26, 2018risk 0.00cvss —epss 0.00
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.
- CVE-2017-1000386Jan 26, 2018risk 0.00cvss —epss 0.00
Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference Parameter' type. This could include, for example,…
- CVE-2017-1000392Jan 26, 2018risk 0.00cvss —epss 0.00
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and…
- CVE-2018-6010Jan 22, 2018risk 0.00cvss —epss 0.01
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and…
- CVE-2018-1045Jan 22, 2018risk 0.00cvss —epss 0.00
In Moodle 3.x, there is XSS via a calendar event name.