Skip to content
Noroxi

CWE-83 · 20 records

Improper Neutralization of Script in Attributes in a Web Page

CVEs in this class

20 records

  • org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability

    CriticalCVSS 9.6Proof of conceptEPSS 1%

    xwiki · xwiki-renderingOct 25, 2023

  • MyBB: Contact page reflected XSS

    CriticalCVSS 9.3No exploitEPSS 1%

    mybb · mybbAug 18, 2026

  • CVAT vulnerable to XSS via skeleton SVG images

    HighCVSS 8.6No exploitEPSS 0%

    cvat · computer vision annotation toolJan 21, 2026

  • An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom F

    HighCVSS 7.8No exploitEPSS 0%

    mozilla · firefoxFeb 22, 2024

  • Kirby: Self cross-site scripting (self-XSS) in the writer field

    HighCVSS 7.4No exploitEPSS 0%

    getkirby · kirbyJul 9, 2026

  • Saleor lacks proper HTML sanitization in rich text fields

    HighCVSS 7.2Proof of conceptEPSS 0%

    saleor · saleorJan 21, 2026

  • CVE-2025-0125
    27Monitor

    PAN-OS: Improper Neutralization of Input in the Management Web Interface

    MediumCVSS 6.9No exploitEPSS 0%

    palo alto networks · cloud ngfwApr 10, 2025

  • Improper Neutralization of Script in Attributes in XWiki (X)HTML renderers

    MediumCVSS 6.1Proof of conceptEPSS 1%

    xwiki · renderingMay 10, 2023

  • DOM XSS in Developer mode dashboard via redirect GET parameter

    MediumCVSS 6.1No exploitEPSS 0%

    zabbix · frontendAug 3, 2023

  • CVE-2026-8245
    24Monitor

    Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection

    MediumCVSS 6.0No exploitEPSS 0%

    concretecms · concrete cmsMay 21, 2026

  • CVE-2024-9103
    24Monitor

    Persistent XSS in blocked messages

    MediumCVSS 6.1No exploitEPSS 0%

    forcepoint · email securityMar 24, 2025

  • Duplicate Advisory: Exported session HTML could keep unsafe markdown links

    MediumCVSS 6.1No exploit

    npm · openclawJun 16, 2026

  • CVE-2025-4615
    22Monitor

    PAN-OS: Improper Neutralization of Input in the Management Web Interface

    MediumCVSS 5.5Proof of conceptEPSS 1%

    paloaltonetworks · pan-osOct 9, 2025

  • Nuxt: Reflected XSS in `navigateTo()` external redirect

    MediumCVSS 5.3No exploitEPSS 0%

    nuxt · nuxtJun 12, 2026

  • Potential cross-site scripting via URLField values in the admin

    MediumCVSS 5.1No exploitEPSS 0%

    djangoproject · djangoAug 4, 2026

  • Stored Cross-Site Scripting (XSS) on login page in GLPI

    MediumCVSS 4.8No exploitEPSS 1%

    glpi-project · glpiNov 3, 2022

  • CVE-2025-0137
    19Monitor

    PAN-OS: Improper Neutralization of Input in the Management Web Interface

    MediumCVSS 4.8No exploitEPSS 0%

    palo alto networks · cloud ngfwMay 14, 2025

  • Stored XSS via unescaped HTML attribute values in earmark

    MediumCVSS 4.8No exploitEPSS 0%

    pragdave · earmarkJun 17, 2026

  • Philips Clinical Collaboration Platform Improper Neutralization of Script in Attributes in a Web Page

    LowCVSS 3.5No exploitEPSS 0%

    philips · clinical collaboration platformSep 18, 2020

  • OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML

    LowCVSS 2.1No exploitEPSS 0%

    openclaw · openclawJun 16, 2026

All vulnerability classes