CWE-81
9 CVEs • Abstraction: Variant
Improper Neutralization of Script in an Error Message Web Page
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters that could be interpreted as web-scripting elements when they are sent to an error page.
CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Docker Mobyproject3Engine MobyMoby/v2Jun 17, 2026 Jun 12, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup...Show more |
A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the contex...Show more |
Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manag...Show more |
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tag...Show more |
1Cvat 1Computer Vision Annotation Tool Jun 17, 2026 Sep 30, 2024 6.3 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate...Show more |
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application. |
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. Th...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Jul 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by sett...Show more |
Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attack...Show more |