Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).

This issue affects CAPEC-63: before 3.0b63.
Published: 2026-10-01
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Monitor
AI Analysis

Impact

The vulnerability arises from improper neutralization of user‑supplied input during web page generation, allowing malicious scripts to be injected and executed in the browsers of other users who view the affected pages. This can lead to credential theft, session hijacking, or defacement of the application.

Affected Systems

The flaw exists in the CAPEC‑63 component, affecting all releases prior to version 3.0b63. No other vendors or products are explicitly listed, so any deployment of CAPEC‑63 before that version remains vulnerable.

Risk and Exploitability

With a CVSS score of 5.8, the vulnerability has moderate severity. The EPSS score is not available and it is not listed in CISA’s KEV catalog, so the current exploit probability is unclear. The likely attack vector involves an attacker sending crafted input—such as a URL parameter or form field—to the affected application, which then reflects unsanitized data back to users, enabling Cross‑Site Scripting attacks.

Generated by OpenCVE AI on October 1, 2026 at 22:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CAPEC‑63 to version 3.0b63 or later, which incorporates the input sanitization fix.
  • Ensure all user input is properly encoded before inclusion in HTML, JavaScript, or CSS contexts; implement output encoding based on the target content type.
  • Apply a strict Content Security Policy to limit script sources and configure a web application firewall to detect and block XSS payloads.

Generated by OpenCVE AI on October 1, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in CAPEC‑63 Before 3.0b63

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.
First Time appeared Cwe-79 - Cross-site Scripting
Cwe-79 - Cross-site Scripting capec-63
Weaknesses CWE-79
CPEs cpe:2.3:a:cwe-79_-_cross-site_scripting:capec-63:*:*:*:*:*:*:*:*
Vendors & Products Cwe-79 - Cross-site Scripting
Cwe-79 - Cross-site Scripting capec-63
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Cwe-79 - Cross-site Scripting Capec-63
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-10-01T21:41:02.568Z

Reserved: 2026-08-06T19:11:09.315Z

Link: CVE-2026-71454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:05.443

Modified: 2026-10-01T22:17:05.443

Link: CVE-2026-71454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')