VYPR

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

VariantIncompleteLikelihood: High

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-18 · CAPEC-193 · CAPEC-32 · CAPEC-86

CVEs mapped to this weakness (602)

page 23 of 31
  • CVE-2023-1384MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.00

    The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

  • CVE-2022-35850MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site…

  • CVE-2022-1274MedMar 29, 2023
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

  • CVE-2022-39348MedOct 26, 2022
    risk 0.28cvss 5.4epss 0.01

    Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response…

  • CVE-2017-20140MedJul 22, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Itech Movie Portal Script 7.36. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /movie.php. The manipulation of the argument f with the input leads to basic cross site…

  • CVE-2017-20061MedJun 20, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site…

  • CVE-2017-20058MedJun 20, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely.…

  • CVE-2017-20057MedJun 20, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version…

  • CVE-2017-20044MedJun 13, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to basic cross site scripting (Reflected). It is possible to initiate the attack remotely. Upgrading to version 4.7.0.0 is able to…

  • CVE-2017-20043MedJun 13, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Navetti PricePoint 4.6.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading to version 4.7.0.0 is…

  • CVE-2017-20033MedJun 10, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in PHPList 3.2.6. This affects an unknown part of the file /lists/admin/. The manipulation of the argument page with the input send\'\";> leads to cross site scripting (Reflected). It is possible…

  • CVE-2017-20027MedJun 9, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting (DOM). The attack may be launched remotely. The exploit has been disclosed to the public and may be…

  • CVE-2017-20026MedJun 9, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting (Reflected). The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-31038MedJun 9, 2022
    risk 0.28cvss 5.4epss 0.01

    Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which…

  • CVE-2020-4046MedJun 12, 2020
    risk 0.28cvss 5.4epss 0.02

    In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in…

  • CVE-2026-65841MedJul 31, 2026
    risk 0.27cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and…

  • CVE-2026-13225MedJun 25, 2026
    risk 0.27cvss epss 0.00

    Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.

  • CVE-2025-65924MedFeb 3, 2026
    risk 0.27cvss 4.1epss 0.00

    ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. As a result, an attacker can…

  • CVE-2025-31326MedJul 8, 2025
    risk 0.27cvss 4.1epss 0.00

    SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application…

  • CVE-2025-29430MedMar 17, 2025
    risk 0.27cvss 4.1epss 0.00

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.