CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
562 vulnerabilities with CWE-80
CVE-2026-48910
MEDIUM
Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
CVSS 6.5
CVE-2026-32822
MEDIUM
dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
CVSS 6.1
CVE-2026-54443
MEDIUM
Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-59838
MEDIUM
Fortinet FortiSIEM - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVSS 5.9
CVE-2026-57167
MEDIUM
PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-59855
HIGH
SiYuan: Store XSS To Rce via Asset.render
CVE-2026-7380
MEDIUM
HTML Injection in Armiya Technologies' Access Control System
CVSS 6.1
CVE-2026-50229
MEDIUM
Apache Tomcat: XSS in number guess example
CVSS 6.1
CVE-2026-57535
LOW
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-57534
LOW
Stored XSS in pretix-pages
CVE-2026-57533
LOW
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-57532
HIGH
Pretix - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-13314
LOW
Stored XSS in pretix-digital
CVE-2026-13225
MEDIUM
pretix - Stored XSS in Ticket Confirmation Page
CVE-2026-52816
MEDIUM
Gogs < 0.14.3 - Unauthenticated Cross-Site Scripting via ipynb Sanitizer
CVE-2026-50146
HIGH
Astro: Reflected XSS via unescaped slot name
CVSS 7.1
CVE-2026-12812
LOW
Radware Cyber Controller HTML Report Generation HTML injection
CVSS 3.5
CVE-2026-46492
HIGH
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
CVSS 7.2
CVE-2026-34033
MEDIUM
Apache Answer: HTML Content Injection in Email
CVSS 5.4
CVE-2026-11511
LOW
Bolt CMS HTML Attribute TextType.php HTML injection
CVSS 3.5
CVE-2026-9646
MEDIUM
ScadaBR Unauthenticated Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-44839
MEDIUM
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVSS 4.8
CVE-2026-39642
MEDIUM
WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-34246
MEDIUM
CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output
CVSS 4.8
CVE-2026-45346
MEDIUM
Open WebUI: Stored Cross-Site Scripting in SVG Renderer
CVSS 5.4
Details
Vulnerabilities
562
Exploit Likelihood
High