CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
538 vulnerabilities with CWE-80
CVE-2023-47869
MEDIUM
wpForo Forum <= 2.2.5 - Cross-Site Scripting
CVSS 4.3
CVE-2023-32193
HIGH
rancher/norman <0.0.0-20240207153100-3bb70b772b52 - Unauthenticated Cross-Site Scripting via Public API Endpoint
CVSS 8.3
CVE-2023-32192
HIGH
rancher/apiserver < 0.0.0-20240207153957-4fd7d821d952 - Unauthenticated Cross-Site Scripting via Public API Endpoint
CVSS 8.3
CVE-2023-35006
MEDIUM
IBM Security QRadar EDR 3.12 - HTML Injection
CVSS 5.4
CVE-2023-49852
MEDIUM
Vsourz Digital Responsive Slick Slider WordPress - Basic XSS
CVSS 6.5
CVE-2023-48285
MEDIUM
Tips and Tricks HQ Stripe Payments <2.0.79 - XSS
CVSS 5.3
CVE-2023-47513
MEDIUM
ARI Stream Quiz < 1.3.2 - Cross-Site Scripting
CVSS 5.4
CVE-2023-46310
MEDIUM
gVectors Team wpDiscuz <7.6.10 - Basic XSS
CVSS 5.3
CVE-2023-45635
MEDIUM
WP Darko Responsive Tabs <4.0.6 - Basic XSS
CVSS 5.4
CVE-2023-45053
MEDIUM
pluginever WP Content Pilot - Basic XSS
CVSS 4.3
CVE-2023-40557
MEDIUM
PickPlugins Tabs & Accordion <1.3.10 - Basic XSS
CVSS 5.4
CVE-2023-39161
MEDIUM
WP Discussion Board Discussion Board < 2.4.8 - Cross-Site Scripting
CVSS 5.4
CVE-2023-23735
MEDIUM
Brainstorm Force Spectra <= 2.3.0 - Unauthenticated Email HTML Injection
CVSS 5.3
CVE-2023-48763
MEDIUM
Crocoblock JetFormBuilder <3.1.4 - Basic XSS
CVSS 5.3
CVE-2023-44396
MEDIUM
iTop < 2.7.1 - Cross-Site Scripting via Dashlet Edit AJAX Endpoint
CVSS 6.8
CVE-2023-43790
MEDIUM
iTop 3.1.0 - Cross-Site Scripting via Object Friendlyname Field
CVSS 5.7
CVE-2023-50933
MEDIUM
IBM PowerSC 1.3, 2.0, and 2.1 - HTML Injection
CVSS 6.1
CVE-2023-5933
MEDIUM
GitLab 13.7-16.6.5, 16.7-16.7.3, 16.8 - Cross-Site Scripting via User Name Input
CVSS 6.4
CVE-2023-20257
MEDIUM
Cisco Prime Infrastructure and Evolved Programmable Network Manager - Authenticated Stored Cross-Site Scripting
CVSS 4.8
CVE-2023-46722
MEDIUM
Pimcore Admin Classic Bundle <1.2.0 - XSS
CVSS 6.1
CVE-2023-46235
MEDIUM
fogproject < 1.5.10.15 - Stored Cross-Site Scripting via Log File Display
CVSS 5.4
CVE-2023-5582
LOW
ZZZCMS 2.2.0 - Cross-Site Scripting in Personal Profile Page
CVSS 3.5
CVE-2023-34354
LOW
Peplink Surf SOHO Firmware - Authenticated Stored Cross-Site Scripting via upload_brand.cgi
CVSS 3.4
CVE-2023-36555
LOW
FortiOS 7.2.0-7.2.4 - Cross-Site Scripting via SAML and Security Fabric Components
CVSS 3.9
CVE-2023-44393
CRITICAL
Piwigo < 14.0.0beta4 - Reflected Cross-Site Scripting via plugin_id Parameter
CVSS 9.3
Details
Vulnerabilities
538
Exploit Likelihood
High