CWE-80 · 459 records
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVEs in this class
460 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2020-13562No exploit | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Medium6.1 | — | 77.7% | Feb 1, 2021 |
47Plan | CVE-2020-13563No exploit | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Medium6.1 | — | 75.9% | Feb 1, 2021 |
47Plan | CVE-2020-13564No exploit | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Medium6.1 | — | 75.9% | Feb 1, 2021 |
45Plan | CVE-2024-4439Proof of concept | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Medium6.1 | — | 71.0% | May 3, 2024 |
44Plan | CVE-2025-30676No exploit | Apache OFBiz: Stored XSS Vulnerabilityapache · ofbiz · CWE-80 | Medium6.1 | — | 67.6% | Apr 1, 2025 |
42Plan | CVE-2022-21145No exploit | A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.lansweeper · lansweeper · CWE-80 | Medium4.8 | — | 77.8% | Apr 14, 2022 |
39Monitor | CVE-2024-32484No exploit | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.ankitects · anki · CWE-80 | High8.2 | — | 22.3% | Jul 22, 2024 |
39Monitor | CVE-2023-39216No exploit | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Critical9.8 | — | 1.2% | Aug 8, 2023 |
38Monitor | CVE-2024-39363No exploit | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505wavlink · wl-wn533a8 firmware · CWE-80 | Medium6.1 | — | 48.1% | Jan 14, 2025 |
38Monitor | CVE-2019-13923No exploit | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).siemens · ie\/wsn-pa link wirelesshart gateway firmware · CWE-80 | Critical9.6 | — | 1.1% | Sep 13, 2019 |
37Monitor | CVE-2025-4278No exploit | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabgitlab · gitlab · CWE-80 | High8.7 | — | 10.6% | Jun 12, 2025 |
37Monitor | CVE-2024-58353No exploit | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Critical9.3 | — | 0.4% | Jul 23, 2026 |
37Monitor | CVE-2024-58355No exploit | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Critical9.3 | — | 0.4% | Jul 23, 2026 |
37Monitor | CVE-2026-91130No exploit | Home Assistant: XSS in Statistics Graph Cardhome-assistant · core · CWE-80 | Critical9.3 | — | 0.4% | Sep 22, 2026 |
37Monitor | CVE-2025-53883No exploit | spacewalk-java has various XSS issues on search pagesuse · container suse manager 5.0 · CWE-80 | Critical9.3 | — | 0.3% | Oct 30, 2025 |
36Monitor | CVE-2025-30161No exploit | OpenEMR Stored XSS in OpenEMR Bronchitis Formopen-emr · openemr · CWE-80 | High8.4 | — | 10.9% | Mar 31, 2025 |
36Monitor | CVE-2021-27915No exploit | XSS Cross-site Scripting Stored (XSS) - Description fieldacquia · mautic · CWE-80 | Critical9.0 | — | 0.6% | Sep 17, 2024 |
36Monitor | CVE-2022-25620No exploit | Stored Cross-Site Scripting (XSS)profelis · sambabox · CWE-80 | Critical9.0 | — | 0.4% | Mar 30, 2022 |
36Monitor | CVE-2024-52300No exploit | macro-pdfviewer has a XSS through the width parameterxwiki · pdf viewer macro · CWE-80 | Critical9.0 | — | 0.4% | Nov 13, 2024 |
36Monitor | CVE-2026-32891No exploit | Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSopenvessl · anchorr · CWE-80 | Critical9.0 | — | 0.3% | Mar 19, 2026 |
35Monitor | CVE-2026-6002No exploit | HTML Injection in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-80 | High8.8 | — | 0.5% | May 7, 2026 |
35Monitor | CVE-2026-57532No exploit | Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in pretix · pretix · CWE-80 | High8.8 | — | 0.4% | Jun 25, 2026 |
35Monitor | CVE-2024-2010No exploit | Reflected XSS in TE Informatics' V5 Softwaretebilisim · v5 · CWE-80 | High8.8 | — | 0.3% | Sep 12, 2024 |
34Monitor | CVE-2025-39663No exploit | Cross Site Scripting through compromised remote sitecheckmk · checkmk · CWE-80 | High8.5 | — | 0.6% | Oct 30, 2025 |
34Monitor | CVE-2026-59855No exploit | SiYuan: Store XSS To Rce via Asset.rendersiyuan-note · siyuan · CWE-80 | High8.6 | — | 0.5% | Jul 9, 2026 |
- CVE-2020-1356247Plan
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
MediumCVSS 6.1No exploitEPSS 78%phpgacl project · phpgaclFeb 1, 2021
- CVE-2020-1356347Plan
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
MediumCVSS 6.1No exploitEPSS 76%phpgacl project · phpgaclFeb 1, 2021
- CVE-2020-1356447Plan
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
MediumCVSS 6.1No exploitEPSS 76%phpgacl project · phpgaclFeb 1, 2021
- CVE-2024-443945Plan
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
MediumCVSS 6.1Proof of conceptEPSS 71%wordpress · wordpressMay 3, 2024
- CVE-2025-3067644Plan
Apache OFBiz: Stored XSS Vulnerability
MediumCVSS 6.1No exploitEPSS 68%apache · ofbizApr 1, 2025
- CVE-2022-2114542Plan
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.
MediumCVSS 4.8No exploitEPSS 78%lansweeper · lansweeperApr 14, 2022
- CVE-2024-3248439Monitor
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.
HighCVSS 8.2No exploitEPSS 22%ankitects · ankiJul 22, 2024
- CVE-2023-3921639Monitor
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
CriticalCVSS 9.8No exploitEPSS 1%zoom · zoomAug 8, 2023
- CVE-2024-3936338Monitor
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505
MediumCVSS 6.1No exploitEPSS 48%wavlink · wl-wn533a8 firmwareJan 14, 2025
- CVE-2019-1392338Monitor
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).
CriticalCVSS 9.6No exploitEPSS 1%siemens · ie\/wsn-pa link wirelesshart gateway firmwareSep 13, 2019
- CVE-2025-427837Monitor
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
HighCVSS 8.7No exploitEPSS 11%gitlab · gitlabJun 12, 2025
- CVE-2024-5835337Monitor
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
CriticalCVSS 9.3No exploitEPSS 0%calcom · cal.diyJul 23, 2026
- CVE-2024-5835537Monitor
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
CriticalCVSS 9.3No exploitEPSS 0%calcom · cal.diyJul 23, 2026
- CVE-2026-9113037Monitor
Home Assistant: XSS in Statistics Graph Card
CriticalCVSS 9.3No exploitEPSS 0%home-assistant · coreSep 22, 2026
- CVE-2025-5388337Monitor
spacewalk-java has various XSS issues on search page
CriticalCVSS 9.3No exploitEPSS 0%suse · container suse manager 5.0Oct 30, 2025
- CVE-2025-3016136Monitor
OpenEMR Stored XSS in OpenEMR Bronchitis Form
HighCVSS 8.4No exploitEPSS 11%open-emr · openemrMar 31, 2025
- CVE-2021-2791536Monitor
XSS Cross-site Scripting Stored (XSS) - Description field
CriticalCVSS 9.0No exploitEPSS 1%acquia · mauticSep 17, 2024
- CVE-2022-2562036Monitor
Stored Cross-Site Scripting (XSS)
CriticalCVSS 9.0No exploitEPSS 0%profelis · sambaboxMar 30, 2022
- CVE-2024-5230036Monitor
macro-pdfviewer has a XSS through the width parameter
CriticalCVSS 9.0No exploitEPSS 0%xwiki · pdf viewer macroNov 13, 2024
- CVE-2026-3289136Monitor
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
CriticalCVSS 9.0No exploitEPSS 0%openvessl · anchorrMar 19, 2026
- CVE-2026-600235Monitor
HTML Injection in DivvyDrive Information Technologies' DivvyDrive
HighCVSS 8.8No exploitEPSS 0%divvydrive information technologies inc. · divvydriveMay 7, 2026
- CVE-2026-5753235Monitor
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in
HighCVSS 8.8No exploitEPSS 0%pretix · pretixJun 25, 2026
- CVE-2024-201035Monitor
Reflected XSS in TE Informatics' V5 Software
HighCVSS 8.8No exploitEPSS 0%tebilisim · v5Sep 12, 2024
- CVE-2025-3966334Monitor
Cross Site Scripting through compromised remote site
HighCVSS 8.5No exploitEPSS 1%checkmk · checkmkOct 30, 2025
- CVE-2026-5985534Monitor
SiYuan: Store XSS To Rce via Asset.render
HighCVSS 8.6No exploitEPSS 1%siyuan-note · siyuanJul 9, 2026