CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 930 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1000495 | — | 0.00 | — | 0.00 | Jan 3, 2018 | QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account | ||
| CVE-2017-1000491 | — | 0.00 | — | 0.00 | Jan 3, 2018 | Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration. | ||
| CVE-2017-1000425 | — | 0.00 | — | 0.00 | Jan 2, 2018 | Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter. | ||
| CVE-2017-1000427 | — | 0.00 | — | 0.00 | Jan 2, 2018 | marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser. | ||
| CVE-2017-1000426 | — | 0.00 | — | 0.00 | Jan 2, 2018 | MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure. | ||
| CVE-2017-1000431 | — | 0.00 | — | 0.00 | Jan 2, 2018 | eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials. | ||
| CVE-2017-1000442 | — | 0.00 | — | 0.00 | Jan 2, 2018 | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | ||
| CVE-2015-7413 | 0.00 | — | 0.00 | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |||
| CVE-2015-7518 | 0.00 | — | 0.00 | Dec 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit… | |||
| CVE-2015-8247 | 0.00 | — | 0.00 | Dec 15, 2015 | Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata. | |||
| CVE-2015-4206 | 0.00 | — | 0.01 | Dec 15, 2015 | Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266. | |||
| CVE-2015-6416 | 0.00 | — | 0.00 | Dec 14, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479. | |||
| CVE-2015-6400 | 0.00 | — | 0.00 | Dec 13, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547. | |||
| CVE-2015-7348 | 0.00 | — | 0.00 | Dec 7, 2015 | Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to demo/en/asyncData/getNodesForBigData.php. | |||
| CVE-2015-6387 | 0.00 | — | 0.00 | Dec 5, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573. | |||
| CVE-2015-6390 | 0.00 | — | 0.00 | Dec 3, 2015 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741. | |||
| CVE-2015-5326 | 0.00 | — | 0.00 | Nov 25, 2015 | Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message. | |||
| CVE-2015-7777 | 0.00 | — | 0.00 | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. | |||
| CVE-2015-7290 | 0.00 | — | 0.01 | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter. | |||
| CVE-2015-7772 | 0.00 | — | 0.00 | Nov 20, 2015 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican… |
- CVE-2017-1000495Jan 3, 2018risk 0.00cvss —epss 0.00
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
- CVE-2017-1000491Jan 3, 2018risk 0.00cvss —epss 0.00
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
- CVE-2017-1000425Jan 2, 2018risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
- CVE-2017-1000427Jan 2, 2018risk 0.00cvss —epss 0.00
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
- CVE-2017-1000426Jan 2, 2018risk 0.00cvss —epss 0.00
MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
- CVE-2017-1000431Jan 2, 2018risk 0.00cvss —epss 0.00
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
- CVE-2017-1000442Jan 2, 2018risk 0.00cvss —epss 0.00
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
- CVE-2015-7413Dec 21, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
- CVE-2015-7518Dec 17, 2015risk 0.00cvss —epss 0.00
Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit…
- CVE-2015-8247Dec 15, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.
- CVE-2015-4206Dec 15, 2015risk 0.00cvss —epss 0.01
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.
- CVE-2015-6416Dec 14, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479.
- CVE-2015-6400Dec 13, 2015risk 0.00cvss —epss 0.00
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.
- CVE-2015-7348Dec 7, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to demo/en/asyncData/getNodesForBigData.php.
- CVE-2015-6387Dec 5, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.
- CVE-2015-6390Dec 3, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.
- CVE-2015-5326Nov 25, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
- CVE-2015-7777Nov 21, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
- CVE-2015-7290Nov 21, 2015risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.
- CVE-2015-7772Nov 20, 2015risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican…