CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,491 vulnerabilities with CWE-79
CVE-2024-40474 MEDIUM
SourceCodester House Rental Management System v1.0 - XSS
CVSS 5.4
CVE-2024-40473 MEDIUM
SourceCodester Best House Rental Management System v1.0 - XSS
CVSS 5.4
CVE-2024-7394 MEDIUM
Concrete CMS < 8.5.18 and 9.0.0-9.3.2 - Authenticated Stored Cross-Site Scripting in getAttributeSetName()
CVSS 4.8
CVE-2024-42366 CRITICAL
VRCX < 2024.03.23 - Remote Code Execution via CefSharp Browser Over-Permission and XSS
CVSS 9.0
CVE-2024-4207 MEDIUM
GitLab 5.1-17.0.5 17.1-17.1.3 17.2-17.2.1 - Cross-Site Scripting via XML File Rendering
CVSS 4.4
CVE-2024-6884 MEDIUM
Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Stored Cross-Site Scripting via Block Options
CVSS 5.4
CVE-2024-6481 MEDIUM
Search & Filter Pro WordPress <2.5.18 - XSS
CVSS 4.8
CVE-2024-5226 MEDIUM
Fuse Social Floating Sidebar <= 5.4.10 - Authenticated Stored Cross-Site Scripting via SVG File Upload
CVSS 6.4
CVE-2024-5668 MEDIUM
FooBox < 2.7.28 - Authenticated DOM-based Stored Cross-Site Scripting via HTML Data Attributes
CVSS 6.4
CVE-2024-6254 MEDIUM
Brizy - Page Builder <= 2.5.1 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 4.3
CVE-2024-6892 MEDIUM
Journyx - Stored Cross-Site Scripting via Crafted Link
CVSS 6.1
CVE-2024-6706 MEDIUM
OpenWebUI - Cross-Site Scripting via Malicious Prompt
CVSS 6.1
CVE-2024-41239 MEDIUM
Responsive School Management System 3.2.0 - Stored Cross-Site Scripting via Class Name Parameter
CVSS 4.8
CVE-2024-41242 MEDIUM
Kashipara Responsive School Management System 3.2.0 - Reflected Cross-Site Scripting via Student Login Error Parameter
CVSS 6.1
CVE-2024-41241 MEDIUM
Kashipara Responsive School Management System v3.2.0 - Reflected Cross-Site Scripting via Admin Login Error Parameter
CVSS 6.1
CVE-2024-41240 MEDIUM
Kashipara Responsive School Management System v3.2.0 - Reflected Cross-Site Scripting via Teacher Login Error Parameter
CVSS 6.1
CVE-2024-20479 MEDIUM
Cisco Identity Services Engine - Authenticated Stored Cross-Site Scripting in Web Management Interface
CVSS 4.8
CVE-2024-20443 MEDIUM
Cisco Identity Services Engine - Authenticated Stored Cross-Site Scripting
CVSS 5.4
CVE-2024-7355 MEDIUM
Organization chart < 1.5.1 - Authenticated Stored Cross-Site Scripting via Title Input and Node Description Parameters
CVSS 4.9
CVE-2024-7353 MEDIUM
Accept Stripe Payments <2.0.86 - XSS
CVSS 5.4
CVE-2024-6494 MEDIUM
WordPress File Upload <4.24.8 - XSS
CVSS 6.1
CVE-2024-3973 MEDIUM
House Manager < 1.0.8.4 - Reflected Cross-Site Scripting via Unsanitized Parameter
CVSS 4.8
CVE-2024-38166 HIGH
Microsoft Dynamics 365 - Unauthenticated Cross-Site Scripting
CVSS 8.2
CVE-2024-28740 CRITICAL
Koha < 23.05.00 - Remote Code Execution via additonal-contents.pl
CVSS 9.6
CVE-2024-28739 HIGH
Koha < 23.05.00 - Remote Code Execution via Format Parameter
CVSS 7.2
Details
Vulnerabilities 45,491
Exploit Likelihood High