Skip to content
Noroxi

CWE-80 · 459 records

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVEs in this class

460 records

  • A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    MediumCVSS 6.1No exploitEPSS 78%

    phpgacl project · phpgaclFeb 1, 2021

  • A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    MediumCVSS 6.1No exploitEPSS 76%

    phpgacl project · phpgaclFeb 1, 2021

  • A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    MediumCVSS 6.1No exploitEPSS 76%

    phpgacl project · phpgaclFeb 1, 2021

  • WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t

    MediumCVSS 6.1Proof of conceptEPSS 71%

    wordpress · wordpressMay 3, 2024

  • Apache OFBiz: Stored XSS Vulnerability

    MediumCVSS 6.1No exploitEPSS 68%

    apache · ofbizApr 1, 2025

  • A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    MediumCVSS 4.8No exploitEPSS 78%

    lansweeper · lansweeperApr 14, 2022

  • An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.

    HighCVSS 8.2No exploitEPSS 22%

    ankitects · ankiJul 22, 2024

  • Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv

    CriticalCVSS 9.8No exploitEPSS 1%

    zoom · zoomAug 8, 2023

  • A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505

    MediumCVSS 6.1No exploitEPSS 48%

    wavlink · wl-wn533a8 firmwareJan 14, 2025

  • A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).

    CriticalCVSS 9.6No exploitEPSS 1%

    siemens · ie\/wsn-pa link wirelesshart gateway firmwareSep 13, 2019

  • CVE-2025-4278
    37Monitor

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab

    HighCVSS 8.7No exploitEPSS 11%

    gitlab · gitlabJun 12, 2025

  • Cal.com through 4.7.15 Cross-Site Scripting via booking questions

    CriticalCVSS 9.3No exploitEPSS 0%

    calcom · cal.diyJul 23, 2026

  • Cal.com through 4.7.15 Cross-Site Scripting via booking questions

    CriticalCVSS 9.3No exploitEPSS 0%

    calcom · cal.diyJul 23, 2026

  • Home Assistant: XSS in Statistics Graph Card

    CriticalCVSS 9.3No exploitEPSS 0%

    home-assistant · coreSep 22, 2026

  • spacewalk-java has various XSS issues on search page

    CriticalCVSS 9.3No exploitEPSS 0%

    suse · container suse manager 5.0Oct 30, 2025

  • OpenEMR Stored XSS in OpenEMR Bronchitis Form

    HighCVSS 8.4No exploitEPSS 11%

    open-emr · openemrMar 31, 2025

  • XSS Cross-site Scripting Stored (XSS) - Description field

    CriticalCVSS 9.0No exploitEPSS 1%

    acquia · mauticSep 17, 2024

  • Stored Cross-Site Scripting (XSS)

    CriticalCVSS 9.0No exploitEPSS 0%

    profelis · sambaboxMar 30, 2022

  • macro-pdfviewer has a XSS through the width parameter

    CriticalCVSS 9.0No exploitEPSS 0%

    xwiki · pdf viewer macroNov 13, 2024

  • Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS

    CriticalCVSS 9.0No exploitEPSS 0%

    openvessl · anchorrMar 19, 2026

  • CVE-2026-6002
    35Monitor

    HTML Injection in DivvyDrive Information Technologies' DivvyDrive

    HighCVSS 8.8No exploitEPSS 0%

    divvydrive information technologies inc. · divvydriveMay 7, 2026

  • Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in

    HighCVSS 8.8No exploitEPSS 0%

    pretix · pretixJun 25, 2026

  • CVE-2024-2010
    35Monitor

    Reflected XSS in TE Informatics' V5 Software

    HighCVSS 8.8No exploitEPSS 0%

    tebilisim · v5Sep 12, 2024

  • Cross Site Scripting through compromised remote site

    HighCVSS 8.5No exploitEPSS 1%

    checkmk · checkmkOct 30, 2025

  • SiYuan: Store XSS To Rce via Asset.render

    HighCVSS 8.6No exploitEPSS 1%

    siyuan-note · siyuanJul 9, 2026

All vulnerability classes