CWE-80 · 459 записей
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE этого класса
466 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2020-13562Эксплойта нет | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Средняя6,1 | — | 77,7 % | 1 февр. 2021 г. |
47В плане | CVE-2020-13563Эксплойта нет | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Средняя6,1 | — | 75,9 % | 1 февр. 2021 г. |
47В плане | CVE-2020-13564Эксплойта нет | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Средняя6,1 | — | 75,9 % | 1 февр. 2021 г. |
45В плане | CVE-2024-4439Proof of concept | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Средняя6,1 | — | 71,0 % | 3 мая 2024 г. |
44В плане | CVE-2025-30676Эксплойта нет | Apache OFBiz: Stored XSS Vulnerabilityapache · ofbiz · CWE-80 | Средняя6,1 | — | 67,6 % | 1 апр. 2025 г. |
42В плане | CVE-2022-21145Эксплойта нет | A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.lansweeper · lansweeper · CWE-80 | Средняя4,8 | — | 77,8 % | 14 апр. 2022 г. |
39Наблюдать | CVE-2024-32484Эксплойта нет | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.ankitects · anki · CWE-80 | Высокая8,2 | — | 22,3 % | 22 июл. 2024 г. |
39Наблюдать | CVE-2023-39216Эксплойта нет | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Критическая9,8 | — | 1,2 % | 8 авг. 2023 г. |
38Наблюдать | CVE-2024-39363Эксплойта нет | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505wavlink · wl-wn533a8 firmware · CWE-80 | Средняя6,1 | — | 48,1 % | 14 янв. 2025 г. |
38Наблюдать | CVE-2019-13923Эксплойта нет | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).siemens · ie\/wsn-pa link wirelesshart gateway firmware · CWE-80 | Критическая9,6 | — | 1,1 % | 13 сент. 2019 г. |
37Наблюдать | CVE-2025-4278Эксплойта нет | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabgitlab · gitlab · CWE-80 | Высокая8,7 | — | 10,6 % | 12 июн. 2025 г. |
37Наблюдать | CVE-2024-58353Эксплойта нет | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Критическая9,3 | — | 0,4 % | 23 июл. 2026 г. |
37Наблюдать | CVE-2024-58355Эксплойта нет | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Критическая9,3 | — | 0,4 % | 23 июл. 2026 г. |
37Наблюдать | CVE-2026-91130Эксплойта нет | Home Assistant: XSS in Statistics Graph Cardhome-assistant · core · CWE-80 | Критическая9,3 | — | 0,4 % | 22 сент. 2026 г. |
37Наблюдать | CVE-2025-53883Эксплойта нет | spacewalk-java has various XSS issues on search pagesuse · container suse manager 5.0 · CWE-80 | Критическая9,3 | — | 0,3 % | 30 окт. 2025 г. |
36Наблюдать | CVE-2025-30161Эксплойта нет | OpenEMR Stored XSS in OpenEMR Bronchitis Formopen-emr · openemr · CWE-80 | Высокая8,4 | — | 10,9 % | 31 мар. 2025 г. |
36Наблюдать | CVE-2021-27915Эксплойта нет | XSS Cross-site Scripting Stored (XSS) - Description fieldacquia · mautic · CWE-80 | Критическая9,0 | — | 0,6 % | 17 сент. 2024 г. |
36Наблюдать | CVE-2022-25620Эксплойта нет | Stored Cross-Site Scripting (XSS)profelis · sambabox · CWE-80 | Критическая9,0 | — | 0,4 % | 30 мар. 2022 г. |
36Наблюдать | CVE-2024-52300Эксплойта нет | macro-pdfviewer has a XSS through the width parameterxwiki · pdf viewer macro · CWE-80 | Критическая9,0 | — | 0,4 % | 13 нояб. 2024 г. |
36Наблюдать | CVE-2026-32891Эксплойта нет | Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSopenvessl · anchorr · CWE-80 | Критическая9,0 | — | 0,3 % | 19 мар. 2026 г. |
35Наблюдать | CVE-2026-6002Эксплойта нет | HTML Injection in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-80 | Высокая8,8 | — | 0,5 % | 7 мая 2026 г. |
35Наблюдать | CVE-2026-57532Эксплойта нет | Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in pretix · pretix · CWE-80 | Высокая8,8 | — | 0,4 % | 25 июн. 2026 г. |
35Наблюдать | CVE-2024-2010Эксплойта нет | Reflected XSS in TE Informatics' V5 Softwaretebilisim · v5 · CWE-80 | Высокая8,8 | — | 0,3 % | 12 сент. 2024 г. |
34Наблюдать | CVE-2025-39663Эксплойта нет | Cross Site Scripting through compromised remote sitecheckmk · checkmk · CWE-80 | Высокая8,5 | — | 0,6 % | 30 окт. 2025 г. |
34Наблюдать | CVE-2026-59855Эксплойта нет | SiYuan: Store XSS To Rce via Asset.rendersiyuan-note · siyuan · CWE-80 | Высокая8,6 | — | 0,5 % | 9 июл. 2026 г. |
- CVE-2020-1356247В плане
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
СредняяCVSS 6,1Эксплойта нетEPSS 78 %phpgacl project · phpgacl1 февр. 2021 г.
- CVE-2020-1356347В плане
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
СредняяCVSS 6,1Эксплойта нетEPSS 76 %phpgacl project · phpgacl1 февр. 2021 г.
- CVE-2020-1356447В плане
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
СредняяCVSS 6,1Эксплойта нетEPSS 76 %phpgacl project · phpgacl1 февр. 2021 г.
- CVE-2024-443945В плане
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
СредняяCVSS 6,1Proof of conceptEPSS 71 %wordpress · wordpress3 мая 2024 г.
- CVE-2025-3067644В плане
Apache OFBiz: Stored XSS Vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 68 %apache · ofbiz1 апр. 2025 г.
- CVE-2022-2114542В плане
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.
СредняяCVSS 4,8Эксплойта нетEPSS 78 %lansweeper · lansweeper14 апр. 2022 г.
- CVE-2024-3248439Наблюдать
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.
ВысокаяCVSS 8,2Эксплойта нетEPSS 22 %ankitects · anki22 июл. 2024 г.
- CVE-2023-3921639Наблюдать
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · zoom8 авг. 2023 г.
- CVE-2024-3936338Наблюдать
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505
СредняяCVSS 6,1Эксплойта нетEPSS 48 %wavlink · wl-wn533a8 firmware14 янв. 2025 г.
- CVE-2019-1392338Наблюдать
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %siemens · ie\/wsn-pa link wirelesshart gateway firmware13 сент. 2019 г.
- CVE-2025-427837Наблюдать
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
ВысокаяCVSS 8,7Эксплойта нетEPSS 11 %gitlab · gitlab12 июн. 2025 г.
- CVE-2024-5835337Наблюдать
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %calcom · cal.diy23 июл. 2026 г.
- CVE-2024-5835537Наблюдать
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %calcom · cal.diy23 июл. 2026 г.
- CVE-2026-9113037Наблюдать
Home Assistant: XSS in Statistics Graph Card
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %home-assistant · core22 сент. 2026 г.
- CVE-2025-5388337Наблюдать
spacewalk-java has various XSS issues on search page
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %suse · container suse manager 5.030 окт. 2025 г.
- CVE-2025-3016136Наблюдать
OpenEMR Stored XSS in OpenEMR Bronchitis Form
ВысокаяCVSS 8,4Эксплойта нетEPSS 11 %open-emr · openemr31 мар. 2025 г.
- CVE-2021-2791536Наблюдать
XSS Cross-site Scripting Stored (XSS) - Description field
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %acquia · mautic17 сент. 2024 г.
- CVE-2022-2562036Наблюдать
Stored Cross-Site Scripting (XSS)
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %profelis · sambabox30 мар. 2022 г.
- CVE-2024-5230036Наблюдать
macro-pdfviewer has a XSS through the width parameter
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %xwiki · pdf viewer macro13 нояб. 2024 г.
- CVE-2026-3289136Наблюдать
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %openvessl · anchorr19 мар. 2026 г.
- CVE-2026-600235Наблюдать
HTML Injection in DivvyDrive Information Technologies' DivvyDrive
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %divvydrive information technologies inc. · divvydrive7 мая 2026 г.
- CVE-2026-5753235Наблюдать
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %pretix · pretix25 июн. 2026 г.
- CVE-2024-201035Наблюдать
Reflected XSS in TE Informatics' V5 Software
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %tebilisim · v512 сент. 2024 г.
- CVE-2025-3966334Наблюдать
Cross Site Scripting through compromised remote site
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %checkmk · checkmk30 окт. 2025 г.
- CVE-2026-5985534Наблюдать
SiYuan: Store XSS To Rce via Asset.render
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %siyuan-note · siyuan9 июл. 2026 г.