Description
The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
Extended Description
While XSS might seem simple to prevent, web browsers vary so widely in how they parse web pages, that a denylist cannot keep track of all the variations. The "XSS Cheat Sheet" [REF-714] contains a large number of attacks that are intended to bypass incomplete denylists.
CVE vulnerabilities with CWE-692 (10)
6.5
CVSS
MEDIUM
CVE-2024-52305
pub. 2024-11-13
6.5
CVSS
MEDIUM
CVE-2023-26047
pub. 2023-03-03
6.1
CVSS
MEDIUM
CVE-2026-71478
pub. 2026-08-06
6.1
CVSS
MEDIUM
CVE-2025-20240
pub. 2025-09-24
5.3
CVSS
MEDIUM
CVE-2024-42214
pub. 2026-07-17
4.6
CVSS
MEDIUM
CVE-2024-30924
pub. 2024-04-18
4.4
CVSS
MEDIUM
CVE-2026-15295
pub. 2026-07-10
4.3
CVSS
MEDIUM
CVE-2024-23569
pub. 2026-07-17
2.9
CVSS
LOW
CVE-2025-49590
pub. 2025-06-18
1.3
CVSS
LOW
CVE-2025-53904
pub. 2025-07-16