CWE-80 · 459 kayıt
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Bu sınıftaki CVE’ler
459 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2020-13562İstismar yok | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Orta6,1 | — | %77,7 | 1 Şub 2021 |
47Planlayın | CVE-2020-13563İstismar yok | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Orta6,1 | — | %75,9 | 1 Şub 2021 |
47Planlayın | CVE-2020-13564İstismar yok | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.phpgacl project · phpgacl · CWE-80 | Orta6,1 | — | %75,9 | 1 Şub 2021 |
45Planlayın | CVE-2024-4439Kavram kanıtı | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Orta6,1 | — | %71,0 | 3 May 2024 |
44Planlayın | CVE-2025-30676İstismar yok | Apache OFBiz: Stored XSS Vulnerabilityapache · ofbiz · CWE-80 | Orta6,1 | — | %67,6 | 1 Nis 2025 |
42Planlayın | CVE-2022-21145İstismar yok | A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.lansweeper · lansweeper · CWE-80 | Orta4,8 | — | %77,8 | 14 Nis 2022 |
39İzleyin | CVE-2024-32484İstismar yok | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.ankitects · anki · CWE-80 | Yüksek8,2 | — | %22,3 | 22 Tem 2024 |
39İzleyin | CVE-2023-39216İstismar yok | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Kritik9,8 | — | %1,2 | 8 Ağu 2023 |
38İzleyin | CVE-2024-39363İstismar yok | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505wavlink · wl-wn533a8 firmware · CWE-80 | Orta6,1 | — | %48,1 | 14 Oca 2025 |
38İzleyin | CVE-2019-13923İstismar yok | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).siemens · ie\/wsn-pa link wirelesshart gateway firmware · CWE-80 | Kritik9,6 | — | %1,1 | 13 Eyl 2019 |
37İzleyin | CVE-2025-4278İstismar yok | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabgitlab · gitlab · CWE-80 | Yüksek8,7 | — | %10,6 | 12 Haz 2025 |
37İzleyin | CVE-2024-58353İstismar yok | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Kritik9,3 | — | %0,4 | 23 Tem 2026 |
37İzleyin | CVE-2024-58355İstismar yok | Cal.com through 4.7.15 Cross-Site Scripting via booking questionscalcom · cal.diy · CWE-80 | Kritik9,3 | — | %0,4 | 23 Tem 2026 |
37İzleyin | CVE-2026-91130İstismar yok | Home Assistant: XSS in Statistics Graph Cardhome-assistant · core · CWE-80 | Kritik9,3 | — | %0,4 | 22 Eyl 2026 |
37İzleyin | CVE-2025-53883İstismar yok | spacewalk-java has various XSS issues on search pagesuse · container suse manager 5.0 · CWE-80 | Kritik9,3 | — | %0,3 | 30 Eki 2025 |
36İzleyin | CVE-2025-30161İstismar yok | OpenEMR Stored XSS in OpenEMR Bronchitis Formopen-emr · openemr · CWE-80 | Yüksek8,4 | — | %10,9 | 31 Mar 2025 |
36İzleyin | CVE-2021-27915İstismar yok | XSS Cross-site Scripting Stored (XSS) - Description fieldacquia · mautic · CWE-80 | Kritik9,0 | — | %0,6 | 17 Eyl 2024 |
36İzleyin | CVE-2022-25620İstismar yok | Stored Cross-Site Scripting (XSS)profelis · sambabox · CWE-80 | Kritik9,0 | — | %0,4 | 30 Mar 2022 |
36İzleyin | CVE-2024-52300İstismar yok | macro-pdfviewer has a XSS through the width parameterxwiki · pdf viewer macro · CWE-80 | Kritik9,0 | — | %0,4 | 13 Kas 2024 |
36İzleyin | CVE-2026-32891İstismar yok | Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSopenvessl · anchorr · CWE-80 | Kritik9,0 | — | %0,3 | 19 Mar 2026 |
35İzleyin | CVE-2026-6002İstismar yok | HTML Injection in DivvyDrive Information Technologies' DivvyDrivedivvydrive information technologies inc. · divvydrive · CWE-80 | Yüksek8,8 | — | %0,5 | 7 May 2026 |
35İzleyin | CVE-2026-57532İstismar yok | Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in pretix · pretix · CWE-80 | Yüksek8,8 | — | %0,4 | 25 Haz 2026 |
35İzleyin | CVE-2024-2010İstismar yok | Reflected XSS in TE Informatics' V5 Softwaretebilisim · v5 · CWE-80 | Yüksek8,8 | — | %0,3 | 12 Eyl 2024 |
34İzleyin | CVE-2025-39663İstismar yok | Cross Site Scripting through compromised remote sitecheckmk · checkmk · CWE-80 | Yüksek8,5 | — | %0,6 | 30 Eki 2025 |
34İzleyin | CVE-2026-59855İstismar yok | SiYuan: Store XSS To Rce via Asset.rendersiyuan-note · siyuan · CWE-80 | Yüksek8,6 | — | %0,5 | 9 Tem 2026 |
- CVE-2020-1356247Planlayın
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
OrtaCVSS 6,1İstismar yokEPSS %78phpgacl project · phpgacl1 Şub 2021
- CVE-2020-1356347Planlayın
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
OrtaCVSS 6,1İstismar yokEPSS %76phpgacl project · phpgacl1 Şub 2021
- CVE-2020-1356447Planlayın
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.
OrtaCVSS 6,1İstismar yokEPSS %76phpgacl project · phpgacl1 Şub 2021
- CVE-2024-443945Planlayın
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
OrtaCVSS 6,1Kavram kanıtıEPSS %71wordpress · wordpress3 May 2024
- CVE-2025-3067644Planlayın
Apache OFBiz: Stored XSS Vulnerability
OrtaCVSS 6,1İstismar yokEPSS %68apache · ofbiz1 Nis 2025
- CVE-2022-2114542Planlayın
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.
OrtaCVSS 4,8İstismar yokEPSS %78lansweeper · lansweeper14 Nis 2022
- CVE-2024-3248439İzleyin
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.
YüksekCVSS 8,2İstismar yokEPSS %22ankitects · anki22 Tem 2024
- CVE-2023-3921639İzleyin
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
KritikCVSS 9,8İstismar yokEPSS %1zoom · zoom8 Ağu 2023
- CVE-2024-3936338İzleyin
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505
OrtaCVSS 6,1İstismar yokEPSS %48wavlink · wl-wn533a8 firmware14 Oca 2025
- CVE-2019-1392338İzleyin
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).
KritikCVSS 9,6İstismar yokEPSS %1siemens · ie\/wsn-pa link wirelesshart gateway firmware13 Eyl 2019
- CVE-2025-427837İzleyin
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
YüksekCVSS 8,7İstismar yokEPSS %11gitlab · gitlab12 Haz 2025
- CVE-2024-5835337İzleyin
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
KritikCVSS 9,3İstismar yokEPSS %0calcom · cal.diy23 Tem 2026
- CVE-2024-5835537İzleyin
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
KritikCVSS 9,3İstismar yokEPSS %0calcom · cal.diy23 Tem 2026
- CVE-2026-9113037İzleyin
Home Assistant: XSS in Statistics Graph Card
KritikCVSS 9,3İstismar yokEPSS %0home-assistant · core22 Eyl 2026
- CVE-2025-5388337İzleyin
spacewalk-java has various XSS issues on search page
KritikCVSS 9,3İstismar yokEPSS %0suse · container suse manager 5.030 Eki 2025
- CVE-2025-3016136İzleyin
OpenEMR Stored XSS in OpenEMR Bronchitis Form
YüksekCVSS 8,4İstismar yokEPSS %11open-emr · openemr31 Mar 2025
- CVE-2021-2791536İzleyin
XSS Cross-site Scripting Stored (XSS) - Description field
KritikCVSS 9,0İstismar yokEPSS %1acquia · mautic17 Eyl 2024
- CVE-2022-2562036İzleyin
Stored Cross-Site Scripting (XSS)
KritikCVSS 9,0İstismar yokEPSS %0profelis · sambabox30 Mar 2022
- CVE-2024-5230036İzleyin
macro-pdfviewer has a XSS through the width parameter
KritikCVSS 9,0İstismar yokEPSS %0xwiki · pdf viewer macro13 Kas 2024
- CVE-2026-3289136İzleyin
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
KritikCVSS 9,0İstismar yokEPSS %0openvessl · anchorr19 Mar 2026
- CVE-2026-600235İzleyin
HTML Injection in DivvyDrive Information Technologies' DivvyDrive
YüksekCVSS 8,8İstismar yokEPSS %0divvydrive information technologies inc. · divvydrive7 May 2026
- CVE-2026-5753235İzleyin
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in
YüksekCVSS 8,8İstismar yokEPSS %0pretix · pretix25 Haz 2026
- CVE-2024-201035İzleyin
Reflected XSS in TE Informatics' V5 Software
YüksekCVSS 8,8İstismar yokEPSS %0tebilisim · v512 Eyl 2024
- CVE-2025-3966334İzleyin
Cross Site Scripting through compromised remote site
YüksekCVSS 8,5İstismar yokEPSS %1checkmk · checkmk30 Eki 2025
- CVE-2026-5985534İzleyin
SiYuan: Store XSS To Rce via Asset.render
YüksekCVSS 8,6İstismar yokEPSS %1siyuan-note · siyuan9 Tem 2026