CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
517 vulnerabilities with CWE-80
CVE-2026-40875
HIGH
mailcow: dockerized vulnerable to stored XSS in user login history real_rip
CVE-2026-40873
HIGH
mailcow: dockerized vulnerable to stored XSS in Quarantine attachment filenames
CVE-2026-40872
CRITICAL
mailcow: dockerized vulnerable to stored XSS in autodiscover logs email address field
CVE-2026-1564
MEDIUM
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
CVSS 4.8
CVE-2026-20170
MEDIUM
Cisco Webex Contact Center - XSS
CVSS 6.1
CVE-2026-40105
MEDIUM
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
CVSS 6.1
CVE-2026-39425
MEDIUM
MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering
CVSS 5.4
CVE-2026-26460
MEDIUM
Vtiger CRM 8.4.0 - HTML Injection
CVSS 6.1
CVE-2026-33657
MEDIUM
EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field
CVSS 4.6
CVE-2026-39941
MEDIUM
ChurchCRM has an XSS vulnerability
CVSS 6.1
CVE-2026-34718
MEDIUM
Zammad improperly neutralizes of script-related HTML tags in ticket articles
CVSS 6.1
CVE-2026-39712
MEDIUM
WordPress tagDiv Composer plugin <= 5.4.3 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39629
MEDIUM
WordPress Uminex theme <= 1.0.9 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39628
MEDIUM
WordPress DukaMarket theme <= 1.3.0 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39626
MEDIUM
WordPress Armania theme <= 1.4.8 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39625
MEDIUM
WordPress TechOne theme <= 3.0.3 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39841
MEDIUM
Stored XSS through list fields on Cargo's page values and Special:CargoTables
CVSS 6.1
CVE-2026-39839
MEDIUM
Stored XSS through URLs in Cargo's map format
CVSS 6.1
CVE-2026-39837
MEDIUM
Stored XSS through the dynamic table format in Cargo
CVSS 5.4
CVE-2026-39344
HIGH
Reflected XSS the login page through the 'username' parameter
CVSS 8.1
CVE-2026-35460
MEDIUM
Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name
CVSS 4.3
CVE-2026-0396
LOW
HTML injection in the web dashboard
CVSS 3.1
CVE-2026-1834
MEDIUM
Ibtana - WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVSS 6.4
CVE-2026-2995
HIGH
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
CVSS 7.7
CVE-2026-33080
HIGH
Filament: Unvalidated Range and Values summarizer values can be used for XSS
CVSS 7.3
Details
Vulnerabilities
517
Exploit Likelihood
High