VYPR

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

VariantIncompleteLikelihood: High

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-18 · CAPEC-193 · CAPEC-32 · CAPEC-86

CVEs mapped to this weakness (602)

page 7 of 31
  • CVE-2024-10621MedNov 8, 2024
    risk 0.42cvss 6.4epss 0.00

    The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

  • CVE-2021-27915HigSep 17, 2024
    risk 0.42cvss 7.6epss 0.01

    Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.

  • CVE-2024-7629MedAug 21, 2024
    risk 0.42cvss 6.4epss 0.00

    The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings function in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-22277MedJul 4, 2024
    risk 0.42cvss 6.4epss 0.00

    VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

  • CVE-2024-6052MedJul 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

  • CVE-2024-5741MedJun 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

  • CVE-2023-49852MedJun 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.

  • CVE-2024-35224HigMay 23, 2024
    risk 0.42cvss 7.6epss 0.00

    OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. This attack requires the…

  • CVE-2023-5933MedJan 26, 2024
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

  • CVE-2023-0007MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when…

  • CVE-2023-22461HigJan 4, 2023
    risk 0.42cvss 7.6epss 0.01

    The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal ``-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream…

  • CVE-2020-8966MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a…

  • CVE-2025-58970MedOct 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.

  • CVE-2024-37732MedJun 24, 2024
    risk 0.41cvss 6.1epss 0.17

    Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

  • CVE-2024-38469MedJun 17, 2024
    risk 0.41cvss 6.3epss 0.00

    zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

  • CVE-2024-34507HigMay 5, 2024
    risk 0.41cvss 7.4epss 0.01

    An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.

  • CVE-2024-31062MedMar 28, 2024
    risk 0.41cvss 6.3epss 0.01

    Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

  • CVE-2024-28417MedMar 14, 2024
    risk 0.41cvss 6.3epss 0.00

    Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

  • CVE-2023-30615MedMay 25, 2023
    risk 0.41cvss 6.3epss 0.00

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations . The vulnerability in allows an attacker to…

  • CVE-2022-23543MedDec 19, 2022
    risk 0.41cvss 6.3epss 0.00

    Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as…