CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
538 vulnerabilities with CWE-80
CVE-2023-1384
MEDIUM
Amazon Fire OS < 6.2.9.5 - Cross-Site Scripting via setMediaSource Function
CVSS 4.3
CVE-2023-22309
MEDIUM
Tribe29 Checkmk Appliance <1.6.4 - XSS
CVSS 6.1
CVE-2023-29508
HIGH
XWiki < 13.10.11 - Stored Cross-Site Scripting via Live Data Macro
CVSS 8.9
CVE-2023-29112
LOW
SAP Application Interface (Message Monitoring) -600,700 - XSS
CVSS 3.7
CVE-2023-29110
LOW
SAP ABAP Platform - Cross-Site Scripting via HTML Tag Injection
CVSS 3.7
CVE-2023-28851
MEDIUM
Silverstripe Form Capture <3.1.1 - XSS
CVSS 6.1
CVE-2023-1013
MEDIUM
Vira-Investing < 1.0.84.86 - Cross-Site Scripting
CVSS 6.1
CVE-2023-26047
MEDIUM
kitabisa/teler-waf < 0.2.0 - Cross-Site Scripting via Hex Entity Bypass
CVSS 6.5
CVE-2023-26046
MEDIUM
kitabisa/teler-waf < 0.1.1 - Cross-Site Scripting via HTML Entity Bypass
CVSS 6.5
CVE-2023-22464
MEDIUM
ViewVC < 1.1.30 and < 1.2.3 - Authenticated Cross-Site Scripting via Unsafe Filename Rendering
CVSS 5.4
CVE-2023-22461
HIGH
sanitize-svg < 0.4.0 - Cross-Site Scripting via Incomplete Deny-List Pattern
CVSS 7.6
CVE-2022-20654
MEDIUM
Cisco Webex Meetings - Unauthenticated Stored Cross-Site Scripting
CVSS 6.1
CVE-2022-38055
MEDIUM
wpForo Forum < 2.0.9 - Cross-Site Scripting
CVSS 4.3
CVE-2022-35850
MEDIUM
FortiAuthenticator 6.1.0-6.3.3 - Unauthenticated Reflected Cross-Site Scripting via Reset-Password Page
CVSS 4.3
CVE-2022-1274
MEDIUM
Keycloak < 20.0.5 - Cross-Site Scripting via Execute-Actions-Email Endpoint
CVSS 5.4
CVE-2022-38210
MEDIUM
Esri Portal for ArcGIS <10.9.1 - XSS
CVSS 6.1
CVE-2022-23543
MEDIUM
silverwaregames < 1.1.34 - Stored Cross-Site Scripting via Custom HTML Attributes in YouTube Iframe
CVSS 6.3
CVE-2022-28703
MEDIUM
Lansweeper 10.1.1.0 - Stored Cross-Site Scripting in HdConfigActions.aspx altertextlanguages
CVSS 5.4
CVE-2022-46350
MEDIUM
SCALANCE X204RNA - XSS
CVSS 6.1
CVE-2022-39372
LOW
GLPI 0.70-10.0.3 - Authenticated Stored Cross-Site Scripting in Account Information
CVSS 3.5
CVE-2022-39371
HIGH
GLPI 10.0.0-10.0.3 - Stored Cross-Site Scripting in Assets Inventory Information
CVSS 7.5
CVE-2022-39277
MEDIUM
GLPI 0.60-10.0.3 - Cross-Site Scripting via External Link Sanitization Bypass
CVSS 4.5
CVE-2022-3844
LOW
Webmin 2.001 - Cross-Site Scripting in xterm/index.cgi
CVSS 3.5
CVE-2022-39348
MEDIUM
Twisted 0.9.4-22.10.0rc1 - Cross-Site Scripting via Host Header in NameVirtualHost
CVSS 5.4
CVE-2022-39301
HIGH
sra-admin < 1.1.1 - Authenticated Stored Cross-Site Scripting via Profile Picture Upload
CVSS 8.2
Details
Vulnerabilities
538
Exploit Likelihood
High