CWE-692— Incomplete Denylist to Cross-Site Scripting
The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.— MITRE CWE catalog
11 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-692page 1 of 1
- CVE-2024-52305MEDIUMCVSS 6.5EG 6.52024-11-13
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. …
- CVE-2023-26047MEDIUMCVSS 6.5EG 6.52023-03-03
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with sp…
- CVE-2026-71478MEDIUMCVSS 6.1EG 6.12026-08-06
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return,…
- CVE-2025-20240MEDIUMCVSS 6.1EG 6.12025-09-24
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to impr…
- CVE-2025-49590MEDIUMCVSS 6.1EG 6.12025-06-18
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that…
- CVE-2026-107396MEDIUMCVSS 5.4EG 5.42026-10-08
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted …
- CVE-2024-42214MEDIUMCVSS 5.3EG 5.32026-07-17
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify th…
- CVE-2024-30924MEDIUMCVSS 4.6EG 4.62024-04-18
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
- CVE-2026-15295MEDIUMCVSS 4.4EG 4.42026-07-10
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. T…
- CVE-2024-23569MEDIUMCVSS 4.3EG 4.32026-07-17
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
- CVE-2025-53904LOWCVSS 1.3EG 1.32025-07-16
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publica…
Map vulnerabilities like CWE-692 to your infrastructure
EchelonGraph correlates every CVE — across CWE-692 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →