CWE-83 · 20 records
Improper Neutralization of Script in Attributes in a Web Page
CVEs in this class
20 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2023-37908Proof of concept | org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerabilityxwiki · xwiki-rendering · CWE-83 | Critical9.6 | — | 1.1% | Oct 25, 2023 |
37Monitor | CVE-2026-45118No exploit | MyBB: Contact page reflected XSSmybb · mybb · CWE-83 | Critical9.3 | — | 0.5% | Aug 18, 2026 |
34Monitor | CVE-2026-23516No exploit | CVAT vulnerable to XSS via skeleton SVG imagescvat · computer vision annotation tool · CWE-83 | High8.6 | — | 0.2% | Jan 21, 2026 |
31Monitor | CVE-2024-26283No exploit | An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Fmozilla · firefox · CWE-83 | High7.8 | — | 0.3% | Feb 22, 2024 |
29Monitor | CVE-2026-49276No exploit | Kirby: Self cross-site scripting (self-XSS) in the writer fieldgetkirby · kirby · CWE-83 | High7.4 | — | 0.4% | Jul 9, 2026 |
28Monitor | CVE-2026-22849Proof of concept | Saleor lacks proper HTML sanitization in rich text fieldssaleor · saleor · CWE-83 | High7.2 | — | 0.2% | Jan 21, 2026 |
27Monitor | CVE-2025-0125No exploit | PAN-OS: Improper Neutralization of Input in the Management Web Interfacepalo alto networks · cloud ngfw · CWE-83 | Medium6.9 | — | 0.4% | Apr 10, 2025 |
24Monitor | CVE-2023-32070Proof of concept | Improper Neutralization of Script in Attributes in XWiki (X)HTML renderersxwiki · rendering · CWE-83 | Medium6.1 | — | 0.7% | May 10, 2023 |
24Monitor | CVE-2023-30958No exploit | DOM XSS in Developer mode dashboard via redirect GET parameterzabbix · frontend · CWE-83 | Medium6.1 | — | 0.4% | Aug 3, 2023 |
24Monitor | CVE-2026-8245No exploit | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injectionconcretecms · concrete cms · CWE-83 | Medium6.0 | — | 0.2% | May 21, 2026 |
24Monitor | CVE-2024-9103No exploit | Persistent XSS in blocked messagesforcepoint · email security · CWE-83 | Medium6.1 | — | 0.2% | Mar 24, 2025 |
24Monitor | GHSA-6xcg-6q43-rj2vNo exploit | Duplicate Advisory: Exported session HTML could keep unsafe markdown linksnpm · openclaw · CWE-83 | Medium6.1 | — | — | Jun 16, 2026 |
22Monitor | CVE-2025-4615Proof of concept | PAN-OS: Improper Neutralization of Input in the Management Web Interfacepaloaltonetworks · pan-os · CWE-83 | Medium5.5 | — | 0.8% | Oct 9, 2025 |
21Monitor | CVE-2026-45669No exploit | Nuxt: Reflected XSS in `navigateTo()` external redirectnuxt · nuxt · CWE-83 | Medium5.3 | — | 0.3% | Jun 12, 2026 |
20Monitor | CVE-2026-15920No exploit | Potential cross-site scripting via URLField values in the admindjangoproject · django · CWE-83 | Medium5.1 | — | 0.4% | Aug 4, 2026 |
19Monitor | CVE-2022-39262No exploit | Stored Cross-Site Scripting (XSS) on login page in GLPIglpi-project · glpi · CWE-83 | Medium4.8 | — | 0.7% | Nov 3, 2022 |
19Monitor | CVE-2025-0137No exploit | PAN-OS: Improper Neutralization of Input in the Management Web Interfacepalo alto networks · cloud ngfw · CWE-83 | Medium4.8 | — | 0.4% | May 14, 2025 |
19Monitor | CVE-2026-48591No exploit | Stored XSS via unescaped HTML attribute values in earmarkpragdave · earmark · CWE-83 | Medium4.8 | — | 0.2% | Jun 17, 2026 |
14Monitor | CVE-2020-14525No exploit | Philips Clinical Collaboration Platform Improper Neutralization of Script in Attributes in a Web Pagephilips · clinical collaboration platform · CWE-83 | Low3.5 | — | 0.5% | Sep 18, 2020 |
8Monitor | CVE-2026-53841No exploit | OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTMLopenclaw · openclaw · CWE-83 | Low2.1 | — | 0.3% | Jun 16, 2026 |
- CVE-2023-3790838Monitor
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
CriticalCVSS 9.6Proof of conceptEPSS 1%xwiki · xwiki-renderingOct 25, 2023
- CVE-2026-4511837Monitor
MyBB: Contact page reflected XSS
CriticalCVSS 9.3No exploitEPSS 1%mybb · mybbAug 18, 2026
- CVE-2026-2351634Monitor
CVAT vulnerable to XSS via skeleton SVG images
HighCVSS 8.6No exploitEPSS 0%cvat · computer vision annotation toolJan 21, 2026
- CVE-2024-2628331Monitor
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom F
HighCVSS 7.8No exploitEPSS 0%mozilla · firefoxFeb 22, 2024
- CVE-2026-4927629Monitor
Kirby: Self cross-site scripting (self-XSS) in the writer field
HighCVSS 7.4No exploitEPSS 0%getkirby · kirbyJul 9, 2026
- CVE-2026-2284928Monitor
Saleor lacks proper HTML sanitization in rich text fields
HighCVSS 7.2Proof of conceptEPSS 0%saleor · saleorJan 21, 2026
- CVE-2025-012527Monitor
PAN-OS: Improper Neutralization of Input in the Management Web Interface
MediumCVSS 6.9No exploitEPSS 0%palo alto networks · cloud ngfwApr 10, 2025
- CVE-2023-3207024Monitor
Improper Neutralization of Script in Attributes in XWiki (X)HTML renderers
MediumCVSS 6.1Proof of conceptEPSS 1%xwiki · renderingMay 10, 2023
- CVE-2023-3095824Monitor
DOM XSS in Developer mode dashboard via redirect GET parameter
MediumCVSS 6.1No exploitEPSS 0%zabbix · frontendAug 3, 2023
- CVE-2026-824524Monitor
Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection
MediumCVSS 6.0No exploitEPSS 0%concretecms · concrete cmsMay 21, 2026
- CVE-2024-910324Monitor
Persistent XSS in blocked messages
MediumCVSS 6.1No exploitEPSS 0%forcepoint · email securityMar 24, 2025
- GHSA-6xcg-6q43-rj2v24Monitor
Duplicate Advisory: Exported session HTML could keep unsafe markdown links
MediumCVSS 6.1No exploitnpm · openclawJun 16, 2026
- CVE-2025-461522Monitor
PAN-OS: Improper Neutralization of Input in the Management Web Interface
MediumCVSS 5.5Proof of conceptEPSS 1%paloaltonetworks · pan-osOct 9, 2025
- CVE-2026-4566921Monitor
Nuxt: Reflected XSS in `navigateTo()` external redirect
MediumCVSS 5.3No exploitEPSS 0%nuxt · nuxtJun 12, 2026
- CVE-2026-1592020Monitor
Potential cross-site scripting via URLField values in the admin
MediumCVSS 5.1No exploitEPSS 0%djangoproject · djangoAug 4, 2026
- CVE-2022-3926219Monitor
Stored Cross-Site Scripting (XSS) on login page in GLPI
MediumCVSS 4.8No exploitEPSS 1%glpi-project · glpiNov 3, 2022
- CVE-2025-013719Monitor
PAN-OS: Improper Neutralization of Input in the Management Web Interface
MediumCVSS 4.8No exploitEPSS 0%palo alto networks · cloud ngfwMay 14, 2025
- CVE-2026-4859119Monitor
Stored XSS via unescaped HTML attribute values in earmark
MediumCVSS 4.8No exploitEPSS 0%pragdave · earmarkJun 17, 2026
- CVE-2020-1452514Monitor
Philips Clinical Collaboration Platform Improper Neutralization of Script in Attributes in a Web Page
LowCVSS 3.5No exploitEPSS 0%philips · clinical collaboration platformSep 18, 2020
- CVE-2026-538418Monitor
OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML
LowCVSS 2.1No exploitEPSS 0%openclaw · openclawJun 16, 2026