İçeriğe atla
Noroxi

CWE-80 · 459 kayıt

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Bu sınıftaki CVE’ler

459 kayıt

  • CVE-2020-13562
    47Planlayın

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    OrtaCVSS 6,1İstismar yokEPSS %78

    phpgacl project · phpgacl1 Şub 2021

  • CVE-2020-13563
    47Planlayın

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    OrtaCVSS 6,1İstismar yokEPSS %76

    phpgacl project · phpgacl1 Şub 2021

  • CVE-2020-13564
    47Planlayın

    A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.

    OrtaCVSS 6,1İstismar yokEPSS %76

    phpgacl project · phpgacl1 Şub 2021

  • CVE-2024-4439
    45Planlayın

    WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t

    OrtaCVSS 6,1Kavram kanıtıEPSS %71

    wordpress · wordpress3 May 2024

  • CVE-2025-30676
    44Planlayın

    Apache OFBiz: Stored XSS Vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %68

    apache · ofbiz1 Nis 2025

  • CVE-2022-21145
    42Planlayın

    A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    OrtaCVSS 4,8İstismar yokEPSS %78

    lansweeper · lansweeper14 Nis 2022

  • CVE-2024-32484
    39İzleyin

    An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.

    YüksekCVSS 8,2İstismar yokEPSS %22

    ankitects · anki22 Tem 2024

  • CVE-2023-39216
    39İzleyin

    Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv

    KritikCVSS 9,8İstismar yokEPSS %1

    zoom · zoom8 Ağu 2023

  • CVE-2024-39363
    38İzleyin

    A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505

    OrtaCVSS 6,1İstismar yokEPSS %48

    wavlink · wl-wn533a8 firmware14 Oca 2025

  • CVE-2019-13923
    38İzleyin

    A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions).

    KritikCVSS 9,6İstismar yokEPSS %1

    siemens · ie\/wsn-pa link wirelesshart gateway firmware13 Eyl 2019

  • CVE-2025-4278
    37İzleyin

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab

    YüksekCVSS 8,7İstismar yokEPSS %11

    gitlab · gitlab12 Haz 2025

  • CVE-2024-58353
    37İzleyin

    Cal.com through 4.7.15 Cross-Site Scripting via booking questions

    KritikCVSS 9,3İstismar yokEPSS %0

    calcom · cal.diy23 Tem 2026

  • CVE-2024-58355
    37İzleyin

    Cal.com through 4.7.15 Cross-Site Scripting via booking questions

    KritikCVSS 9,3İstismar yokEPSS %0

    calcom · cal.diy23 Tem 2026

  • CVE-2026-91130
    37İzleyin

    Home Assistant: XSS in Statistics Graph Card

    KritikCVSS 9,3İstismar yokEPSS %0

    home-assistant · core22 Eyl 2026

  • CVE-2025-53883
    37İzleyin

    spacewalk-java has various XSS issues on search page

    KritikCVSS 9,3İstismar yokEPSS %0

    suse · container suse manager 5.030 Eki 2025

  • CVE-2025-30161
    36İzleyin

    OpenEMR Stored XSS in OpenEMR Bronchitis Form

    YüksekCVSS 8,4İstismar yokEPSS %11

    open-emr · openemr31 Mar 2025

  • CVE-2021-27915
    36İzleyin

    XSS Cross-site Scripting Stored (XSS) - Description field

    KritikCVSS 9,0İstismar yokEPSS %1

    acquia · mautic17 Eyl 2024

  • CVE-2022-25620
    36İzleyin

    Stored Cross-Site Scripting (XSS)

    KritikCVSS 9,0İstismar yokEPSS %0

    profelis · sambabox30 Mar 2022

  • CVE-2024-52300
    36İzleyin

    macro-pdfviewer has a XSS through the width parameter

    KritikCVSS 9,0İstismar yokEPSS %0

    xwiki · pdf viewer macro13 Kas 2024

  • CVE-2026-32891
    36İzleyin

    Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS

    KritikCVSS 9,0İstismar yokEPSS %0

    openvessl · anchorr19 Mar 2026

  • CVE-2026-6002
    35İzleyin

    HTML Injection in DivvyDrive Information Technologies' DivvyDrive

    YüksekCVSS 8,8İstismar yokEPSS %0

    divvydrive information technologies inc. · divvydrive7 May 2026

  • CVE-2026-57532
    35İzleyin

    Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in

    YüksekCVSS 8,8İstismar yokEPSS %0

    pretix · pretix25 Haz 2026

  • CVE-2024-2010
    35İzleyin

    Reflected XSS in TE Informatics' V5 Software

    YüksekCVSS 8,8İstismar yokEPSS %0

    tebilisim · v512 Eyl 2024

  • CVE-2025-39663
    34İzleyin

    Cross Site Scripting through compromised remote site

    YüksekCVSS 8,5İstismar yokEPSS %1

    checkmk · checkmk30 Eki 2025

  • CVE-2026-59855
    34İzleyin

    SiYuan: Store XSS To Rce via Asset.render

    YüksekCVSS 8,6İstismar yokEPSS %1

    siyuan-note · siyuan9 Tem 2026

Tüm zafiyet sınıfları