VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 93 of 2,331
  • CVE-2023-0786HigFeb 12, 2023
    risk 0.48cvss 8.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2022-46147HigNov 28, 2022
    risk 0.48cvss 8.4epss 0.01

    Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.…

  • CVE-2022-2904HigNov 2, 2022
    risk 0.48cvss 7.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external…

  • CVE-2022-3608HigOct 19, 2022
    risk 0.48cvss 8.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

  • CVE-2022-2865HigOct 17, 2022
    risk 0.48cvss 7.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers…

  • CVE-2022-2527HigOct 17, 2022
    risk 0.48cvss 7.3epss 0.01

    An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary…

  • CVE-2021-43776HigNov 26, 2021
    risk 0.48cvss 7.4epss 0.01

    Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate…

  • CVE-2021-38295HigOct 14, 2021
    risk 0.48cvss 7.3epss 0.03

    In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML…

  • CVE-2021-40457HigOct 13, 2021
    risk 0.48cvss 7.4epss 0.02

    Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

  • CVE-2021-22261HigOct 5, 2021
    risk 0.48cvss 7.3epss 0.01

    A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code…

  • CVE-2021-39887HigOct 5, 2021
    risk 0.48cvss 7.3epss 0.01

    A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

  • CVE-2021-37634HigAug 9, 2021
    risk 0.48cvss 7.4epss 0.01

    Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as…

  • CVE-2021-21084HigJun 28, 2021
    risk 0.48cvss 7.3epss 0.02

    AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.…

  • CVE-2021-21004HigJun 25, 2021
    risk 0.48cvss 7.4epss 0.01

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

  • CVE-2021-1571HigJun 16, 2021
    risk 0.48cvss 7.2epss 0.10

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2021-1543HigJun 16, 2021
    risk 0.48cvss 7.2epss 0.09

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2020-29029HigMar 5, 2021
    risk 0.48cvss 7.3epss 0.01

    Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

  • CVE-2020-35947HigJan 1, 2021
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of…

  • CVE-2020-1345HigSep 11, 2020
    risk 0.48cvss 7.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-1198HigSep 11, 2020
    risk 0.48cvss 7.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…