CWE-80— Improper Neutralization of Script-Related HTML Tags
522 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-80page 6 of 11
- CVE-2024-25690MEDIUMCVSS 4.7EG 4.72024-04-04
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
- CVE-2024-25865MEDIUMCVSS 6.1EG 6.12024-03-02
Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.
- CVE-2024-25873MEDIUMCVSS 5.4EG 5.42024-02-22
Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- CVE-2024-26282HIGHCVSS 7.1EG 7.12024-02-22
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
- CVE-2024-26482HIGHCVSS 7.1EG 7.12024-02-22
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is back…
- CVE-2024-27306MEDIUMCVSS 6.1EG 6.12024-04-18
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy serv…
- CVE-2024-27716MEDIUMCVSS 5.4EG 5.42024-07-05
Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.
- CVE-2024-28108MEDIUMCVSS 4.7EG 4.72024-03-25
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page …
- CVE-2024-28417MEDIUMCVSS 6.3EG 6.32024-03-14
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
- CVE-2024-28831MEDIUMCVSS 5.4EG 5.42024-06-25
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.
- CVE-2024-28832MEDIUMCVSS 4.8EG 4.82024-06-25
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Repor…
- CVE-2024-31062MEDIUMCVSS 6.3EG 6.32024-03-28
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.
- CVE-2024-32464MEDIUMCVSS 6.1EG 6.12024-06-04
Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is fixed in 7.1.3.4 and 7…
- CVE-2024-32472MEDIUMCVSS 6.1EG 6.12024-04-17
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. Ther…
- CVE-2024-32484HIGHCVSS 7.4EG 7.42024-07-22
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can s…
- CVE-2024-32489MEDIUMCVSS 6.1EG 6.12024-04-15
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
- CVE-2024-32746MEDIUMCVSS 4.6EG 4.62024-04-17
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.
- CVE-2024-32790MEDIUMCVSS 4.3EG 4.32024-05-17
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.
- CVE-2024-32875MEDIUMCVSS 6.1EG 6.12024-04-23
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks en…
- CVE-2024-32966MEDIUMCVSS 5.8EG 5.82024-05-01
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a…
- CVE-2024-33423HIGHCVSS 7.4EG 7.42024-05-01
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section.
- CVE-2024-33831HIGHCVSS 7.4EG 7.42024-04-30
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field.
- CVE-2024-34070CRITICALCVSS 9.6EG 9.62024-05-14
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User …
- CVE-2024-34398MEDIUMCVSS 4.2EG 4.22025-03-12
An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.
- CVE-2024-34507HIGHCVSS 7.4EG 7.42024-05-05
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:Recen…
- CVE-2024-34699MEDIUMCVSS 6.5EG 6.52024-05-14
GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.
- CVE-2024-35112MEDIUMCVSS 5.4EG 5.42025-01-25
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
- CVE-2024-35224HIGHCVSS 7.6EG 7.62024-05-23
OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header…
- CVE-2024-35680MEDIUMCVSS 5.3EG 5.32024-06-10
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through…
- CVE-2024-36395MEDIUMCVSS 6.1EG 6.12024-06-13
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CVE-2024-37156MEDIUMCVSS 6.1EG 6.12024-06-06
The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.
- CVE-2024-37166HIGHCVSS 8.9EG 8.92024-06-10
ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases. Version 2.0.0 introduces chan…
- CVE-2024-37297MEDIUMCVSS 5.4EG 5.42024-06-12
WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While th…
- CVE-2024-37732MEDIUMCVSS 6.1EG 6.12024-06-24
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
- CVE-2024-38039MEDIUMCVSS 5.4EG 5.42024-10-04
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (n…
- CVE-2024-38318MEDIUMCVSS 4.8EG 4.82025-02-05
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting si…
- CVE-2024-38469MEDIUMCVSS 6.3EG 6.32024-06-17
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.
- CVE-2024-38859MEDIUMCVSS 6.1EG 6.12024-08-26
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These …
- CVE-2024-39363CRITICALCVSS 9.6EG 9.62025-01-14
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker c…
- CVE-2024-41693MEDIUMCVSS 6.1EG 6.12024-07-30
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CVE-2024-41697MEDIUMCVSS 6.1EG 6.12024-08-20
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CVE-2024-41752MEDIUMCVSS 5.4EG 5.42024-12-18
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security…
- CVE-2024-41810MEDIUMCVSS 6.1EG 6.12024-07-29
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL …
- CVE-2024-41947CRITICALCVSS 9.0EG 9.02024-07-31
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets o…
- CVE-2024-4214LOWCVSS 2.7EG 2.72024-05-17
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.
- CVE-2024-42195LOWCVSS 3.1EG 3.12024-12-05
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
- CVE-2024-4439HIGHCVSS 7.2EG 9.02024-05-03
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attack…
- CVE-2024-45406MEDIUMCVSS 5.5EG 5.52024-09-09
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
- CVE-2024-46910HIGHCVSS 7.1EG 7.12025-02-13
An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.
- CVE-2024-47139MEDIUMCVSS 6.8EG 6.82024-10-16
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. …
Map vulnerabilities like CWE-80 to your infrastructure
EchelonGraph correlates every CVE — across CWE-80 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →