CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

562 vulnerabilities with CWE-80
CVE-2026-48910 MEDIUM
Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
CVSS 6.5
CVE-2026-32822 MEDIUM
dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
CVSS 6.1
CVE-2026-54443 MEDIUM
Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-59838 MEDIUM
Fortinet FortiSIEM - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVSS 5.9
CVE-2026-57167 MEDIUM
PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-59855 HIGH
SiYuan: Store XSS To Rce via Asset.render
CVE-2026-7380 MEDIUM
HTML Injection in Armiya Technologies' Access Control System
CVSS 6.1
CVE-2026-50229 MEDIUM
Apache Tomcat: XSS in number guess example
CVSS 6.1
CVE-2026-57535 LOW
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-57534 LOW
Stored XSS in pretix-pages
CVE-2026-57533 LOW
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-57532 HIGH
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-13314 LOW
Stored XSS in pretix-digital
CVE-2026-13225 MEDIUM
pretix - Stored XSS in Ticket Confirmation Page
CVE-2026-52816 MEDIUM
Gogs < 0.14.3 - Unauthenticated Cross-Site Scripting via ipynb Sanitizer
CVE-2026-50146 HIGH
Astro: Reflected XSS via unescaped slot name
CVSS 7.1
CVE-2026-12812 LOW
Radware Cyber Controller HTML Report Generation HTML injection
CVSS 3.5
CVE-2026-46492 HIGH
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
CVSS 7.2
CVE-2026-34033 MEDIUM
Apache Answer: HTML Content Injection in Email
CVSS 5.4
CVE-2026-11511 LOW
Bolt CMS HTML Attribute TextType.php HTML injection
CVSS 3.5
CVE-2026-9646 MEDIUM
ScadaBR Unauthenticated Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-44839 MEDIUM
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVSS 4.8
CVE-2026-39642 MEDIUM
WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-34246 MEDIUM
CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output
CVSS 4.8
CVE-2026-45346 MEDIUM
Open WebUI: Stored Cross-Site Scripting in SVG Renderer
CVSS 5.4
Details
Vulnerabilities 562
Exploit Likelihood High