CWE-707

Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

251 vulnerabilities with CWE-707
CVE-2022-4416 MEDIUM
mxsdoc - SQL Injection via searchWord/reposId Parameter in getReposAllUsers Function
CVSS 6.3
CVE-2022-4403 MEDIUM
Canteen Management System - SQL Injection via customer_id Parameter in ajax_represent.php
CVSS 6.3
CVE-2022-4401 LOW
pallidlight online-course-selection-system - Cross-Site Scripting
CVSS 3.5
CVE-2022-4400 LOW
FS-Blog - Cross-Site Scripting in Title Handler
CVSS 3.5
CVE-2022-4399 MEDIUM
TicklishHoneyBee nodau - SQL Injection
CVSS 5.5
CVE-2022-4396 LOW
pyrdfa3 < 3.6.2 - Cross-Site Scripting in _get_option Function
CVSS 3.5
CVE-2022-4377 LOW
S-CMS 5.0 Build 20220328 - Cross-Site Scripting via Contact Information Page
CVSS 3.5
CVE-2022-4375 MEDIUM
Mingsoft MCMS <5.2.9 - SQL Injection
CVSS 6.3
CVE-2022-4354 MEDIUM
pb-cms 2.0 - Cross-Site Scripting in Message Board Comment Handler
CVSS 4.3
CVE-2022-4353 LOW
pb-cms 2.0 - Cross-Site Scripting in IpUtil.getIpAddr
CVSS 3.5
CVE-2022-4350 LOW
Mingsoft MCMS 5.2.8 - Cross-Site Scripting via search.do content_title Parameter
CVSS 3.5
CVE-2022-4348 LOW
RuoYi-Cloud - Cross-Site Scripting in JSON Handler
CVSS 3.5
CVE-2022-4347 LOW
beetl-bbs - Cross-Site Scripting via User Argument in WebUtils.java
CVSS 3.5
CVE-2022-4341 LOW
coder-chain_gdut - Cross-Site Scripting in /back/index.php/user/User
CVSS 3.5
CVE-2022-4322 MEDIUM
maku-boot 1.3.0-2.2.0 - SQL Injection in Scheduled Task Handler
CVSS 6.3
CVE-2022-4300 MEDIUM
FastCMS - Remote Code Execution via Template Handler
CVSS 6.3
CVE-2022-4282 MEDIUM
SpringBootCMS - Remote Code Execution via Template Injection
CVSS 4.7
CVE-2022-4279 LOW
SourceCodester Human Resource Management System 1.0 - Cross-Site Scripting via Employee View Search Parameter
CVSS 3.5
CVE-2022-4278 MEDIUM
SourceCodester Human Resource Management System 1.0 - SQL Injection via empid Parameter
CVSS 4.7
CVE-2022-4277 MEDIUM
Shaoxing Background Management System - SQL Injection via /Default/Bd id Parameter
CVSS 6.3
CVE-2022-4275 MEDIUM
House Rental System - SQL Injection via search-property.php POST Request Handler
CVSS 6.3
CVE-2022-4274 MEDIUM
House Rental System - SQL Injection via property_id Parameter in view-property.php
CVSS 6.3
CVE-2022-4257 MEDIUM
C-DATA Web Management System - Argument Injection
CVSS 6.3
CVE-2022-4253 LOW
Canteen Management System - Cross-Site Scripting via customer.php builtin_echo Function
CVSS 3.5
CVE-2022-4252 LOW
Canteen Management System - Cross-Site Scripting in categories.php builtin_echo Function
CVSS 3.5
Details
Vulnerabilities 251