CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
538 vulnerabilities with CWE-80
CVE-2024-47815
MEDIUM
IncidentReporting - Authenticated Cross-Site Scripting
CVSS 6.0
CVE-2024-47812
MEDIUM
ImportDump - Stored Cross-Site Scripting in Special:RequestImportQueue Date Messages
CVSS 6.0
CVE-2024-47782
HIGH
WikiDiscover < 2024-10-06 - Stored Cross-Site Scripting in Special:WikiDiscover Page
CVSS 7.6
CVE-2024-38039
MEDIUM
Esri Portal for ArcGIS <=11.0 - XSS
CVSS 5.4
CVE-2024-47765
MEDIUM
jgniecki/minecraft_motd_parser < 1.0.6 - Cross-Site Scripting via Malformed MOTD Color and Text Properties
CVSS 6.1
CVE-2024-47612
LOW
DataDump < 601688ee8e8808a23b102fa305b178f27cbd226d - Stored Cross-Site Scripting via Unescaped Interface Messages
CVSS 3.5
CVE-2024-8981
HIGH
Broken Link Checker <= 2.4.0 - Unauthenticated Reflected Cross-Site Scripting via add_query_arg
CVSS 7.1
CVE-2024-47536
MEDIUM
starcitizen.tools/citizen < 2.31.0 - Stored Cross-Site Scripting via Real Name Field
CVSS 5.4
CVE-2024-8872
MEDIUM
Store Hours for WooCommerce < 4.3.20 - Unauthenticated Reflected Cross-Site Scripting via add_query_arg
CVSS 6.1
CVE-2024-8680
MEDIUM
MC4WP: Mailchimp for WordPress <4.9.16 - XSS
CVSS 4.4
CVE-2024-2010
MEDIUM
Tebilisim V5 < 6.2 - Basic XSS
CVSS 6.1
CVE-2024-45406
MEDIUM
Craft CMS 5.0.0-5.1.1 - Stored Cross-Site Scripting in Breadcrumb List and Title Fields
CVSS 5.5
CVE-2024-38859
MEDIUM
Checkmk < 2.3.0p14, < 2.2.0p33, < 2.1.0p47 - Stored Cross-Site Scripting in SLA Column Title
CVSS 6.1
CVE-2024-8145
LOW
ClassCMS 4.8 - Cross-Site Scripting via Article Title Parameter
CVSS 2.4
CVE-2024-7629
MEDIUM
Responsive video < 1.0 - Authenticated Stored Cross-Site Scripting via Video Settings Function
CVSS 6.4
CVE-2024-41697
MEDIUM
Priority < 24.0 - Cross-Site Scripting
CVSS 6.1
CVE-2024-41947
CRITICAL
XWiki 11.8-15.10.7 - Stored Cross-Site Scripting via Edit Conflict
CVSS 9.0
CVE-2024-41693
MEDIUM
Mashov < 3.8.46 - Cross-Site Scripting
CVSS 6.1
CVE-2024-41810
MEDIUM
twisted < 24.7.0rc1 - Reflected Cross-Site Scripting via redirectTo Function
CVSS 6.1
CVE-2024-32484
HIGH
Anki 24.04 - Reflected Cross-Site Scripting via Invalid Path Handling
CVSS 7.4
CVE-2024-25639
MEDIUM
khoj < 1.13.0 - Cross-Site Scripting via AI Model Response and User Input
CVSS 5.9
CVE-2024-27716
MEDIUM
Eskooly Web Product < 3.0 - Cross-Site Scripting via Message Sending and User Input Fields
CVSS 5.4
CVE-2024-22277
MEDIUM
VMware Cloud Director Availability - XSS
CVSS 6.4
CVE-2024-6052
MEDIUM
checkmk < 2.3.0p8, 2.2.0p29, 2.1.0p45 - Stored Cross-Site Scripting via HTML Element Injection
CVSS 6.5
CVE-2024-28832
MEDIUM
Checkmk < 2.3.0p7, < 2.2.0p28, < 2.1.0p45 - Stored Cross-Site Scripting in Crash Report Page
CVSS 4.8
Details
Vulnerabilities
538
Exploit Likelihood
High