CWE-82Variant

Improper Neutralization of Script in Attributes of IMG Tags in a Web Page

Incomplete in the CWE catalog ยท 7 CVEs mapped

7
CVEs mapped
9.1
Median CVSS
What it is

The web application does not neutralize or incorrectly neutralizes scripting elements within attributes of HTML IMG tags, such as the src attribute.

Recent examples
8.5cvss
CVE-2025-53194

WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerability

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Code Injection.This issue affects JetEngine: from n/a through <= 3.7.0.

HIGHno explanation yet
0%
epss
9.9cvss
CVE-2024-52427

WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability

๐Ÿšจ A sneaky deserialization vulnerability in Vollstart Event Tickets could let attackers run arbitrary commands on your server โ€” think of it as giving a free pass to anyone who asks for it! ๐Ÿ”ฅ Imagine your event ticketing system is a fancy restaurant where anyone can submit a special request without checking the ingredients. If the chef just goes ahead and prepares whatever they ask for, you could end up serving all sorts of questionable dishes to your guests! This vulnerability allows an attacker to potentially execute malicious commands on your server, leading to data breaches, service interruptions, or even total system takeover. It's a ticket to chaos that could leave your users in the lurch and your reputation in tatters!

CRITICAL
1%
epss
9.1cvss
CVE-2024-52434

WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability

๐Ÿšจ A crafty command injection flaw lurks in Popup by Supsystic, allowing attackers to execute arbitrary commands on your server! ๐Ÿ”ฅ Think of it like a restaurant that allows any diner to sneak into the kitchen with a fake order โ€” they could cook up anything they want, potentially ruining the whole meal. This vulnerability gives attackers that same kind of access, only to your server instead! If an attacker exploits this deserialization of untrusted data vulnerability, they could gain full control of your server environment. That means reading sensitive data, modifying files, or even launching further attacks without any barriers โ€” absolutely devastating!

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-82
Abstraction
Variant
Structure
Simple
Status
Incomplete