VYPR

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

VariantIncompleteLikelihood: High

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-18 · CAPEC-193 · CAPEC-32 · CAPEC-86

CVEs mapped to this weakness (602)

page 20 of 31
  • CVE-2025-27099MedMar 3, 2025
    risk 0.31cvss 4.8epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other…

  • CVE-2024-38318MedFeb 5, 2025
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2024-28832MedJun 25, 2024
    risk 0.31cvss 4.8epss 0.00

    Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

  • CVE-2024-32966MedMay 1, 2024
    risk 0.31cvss 5.8epss 0.00

    Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a malicious file name like `<img src=x…

  • CVE-2024-25690MedApr 4, 2024
    risk 0.31cvss 4.7epss 0.00

    There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

  • CVE-2023-20257MedJan 17, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management…

  • CVE-2023-20222MedAug 16, 2023
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected…

  • CVE-2023-24497MedJul 6, 2023
    risk 0.31cvss 4.7epss 0.01

    Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these…

  • CVE-2023-24496MedJul 6, 2023
    risk 0.31cvss 4.7epss 0.01

    Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these…

  • CVE-2022-20765MedMay 27, 2022
    risk 0.31cvss 4.8epss 0.01

    A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by…

  • CVE-2021-1420MedApr 8, 2021
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this…

  • CVE-2020-11001MedApr 14, 2020
    risk 0.31cvss 5.8epss 0.01

    In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision comparison view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could potentially craft a page revision…

  • CVE-2026-44259MedMay 12, 2026
    risk 0.30cvss 4.6epss 0.00

    efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or…

  • CVE-2025-31992MedOct 12, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.

  • CVE-2025-52654MedOct 3, 2025
    risk 0.30cvss 4.6epss 0.00

    HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

  • CVE-2025-27358MedJul 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This issue affects Frontend File Manager: from n/a through <= 23.6.

  • CVE-2025-29426MedMar 17, 2025
    risk 0.30cvss 4.6epss 0.00

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.

  • CVE-2024-54128MedDec 5, 2024
    risk 0.30cvss 5.7epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making…

  • CVE-2024-32746MedApr 17, 2024
    risk 0.30cvss 4.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.

  • CVE-2024-2380MedApr 5, 2024
    risk 0.30cvss 4.6epss 0.00

    Stored XSS in graph rendering in Checkmk <2.3.0b4.