CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

538 vulnerabilities with CWE-80
CVE-2024-47815 MEDIUM
IncidentReporting - Authenticated Cross-Site Scripting
CVSS 6.0
CVE-2024-47812 MEDIUM
ImportDump - Stored Cross-Site Scripting in Special:RequestImportQueue Date Messages
CVSS 6.0
CVE-2024-47782 HIGH
WikiDiscover < 2024-10-06 - Stored Cross-Site Scripting in Special:WikiDiscover Page
CVSS 7.6
CVE-2024-38039 MEDIUM
Esri Portal for ArcGIS <=11.0 - XSS
CVSS 5.4
CVE-2024-47765 MEDIUM
jgniecki/minecraft_motd_parser < 1.0.6 - Cross-Site Scripting via Malformed MOTD Color and Text Properties
CVSS 6.1
CVE-2024-47612 LOW
DataDump < 601688ee8e8808a23b102fa305b178f27cbd226d - Stored Cross-Site Scripting via Unescaped Interface Messages
CVSS 3.5
CVE-2024-8981 HIGH
Broken Link Checker <= 2.4.0 - Unauthenticated Reflected Cross-Site Scripting via add_query_arg
CVSS 7.1
CVE-2024-47536 MEDIUM
starcitizen.tools/citizen < 2.31.0 - Stored Cross-Site Scripting via Real Name Field
CVSS 5.4
CVE-2024-8872 MEDIUM
Store Hours for WooCommerce < 4.3.20 - Unauthenticated Reflected Cross-Site Scripting via add_query_arg
CVSS 6.1
CVE-2024-8680 MEDIUM
MC4WP: Mailchimp for WordPress <4.9.16 - XSS
CVSS 4.4
CVE-2024-2010 MEDIUM
Tebilisim V5 < 6.2 - Basic XSS
CVSS 6.1
CVE-2024-45406 MEDIUM
Craft CMS 5.0.0-5.1.1 - Stored Cross-Site Scripting in Breadcrumb List and Title Fields
CVSS 5.5
CVE-2024-38859 MEDIUM
Checkmk < 2.3.0p14, < 2.2.0p33, < 2.1.0p47 - Stored Cross-Site Scripting in SLA Column Title
CVSS 6.1
CVE-2024-8145 LOW
ClassCMS 4.8 - Cross-Site Scripting via Article Title Parameter
CVSS 2.4
CVE-2024-7629 MEDIUM
Responsive video < 1.0 - Authenticated Stored Cross-Site Scripting via Video Settings Function
CVSS 6.4
CVE-2024-41697 MEDIUM
Priority < 24.0 - Cross-Site Scripting
CVSS 6.1
CVE-2024-41947 CRITICAL
XWiki 11.8-15.10.7 - Stored Cross-Site Scripting via Edit Conflict
CVSS 9.0
CVE-2024-41693 MEDIUM
Mashov < 3.8.46 - Cross-Site Scripting
CVSS 6.1
CVE-2024-41810 MEDIUM
twisted < 24.7.0rc1 - Reflected Cross-Site Scripting via redirectTo Function
CVSS 6.1
CVE-2024-32484 HIGH
Anki 24.04 - Reflected Cross-Site Scripting via Invalid Path Handling
CVSS 7.4
CVE-2024-25639 MEDIUM
khoj < 1.13.0 - Cross-Site Scripting via AI Model Response and User Input
CVSS 5.9
CVE-2024-27716 MEDIUM
Eskooly Web Product < 3.0 - Cross-Site Scripting via Message Sending and User Input Fields
CVSS 5.4
CVE-2024-22277 MEDIUM
VMware Cloud Director Availability - XSS
CVSS 6.4
CVE-2024-6052 MEDIUM
checkmk < 2.3.0p8, 2.2.0p29, 2.1.0p45 - Stored Cross-Site Scripting via HTML Element Injection
CVSS 6.5
CVE-2024-28832 MEDIUM
Checkmk < 2.3.0p7, < 2.2.0p28, < 2.1.0p45 - Stored Cross-Site Scripting in Crash Report Page
CVSS 4.8
Details
Vulnerabilities 538
Exploit Likelihood High