CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

538 vulnerabilities with CWE-80
CVE-2023-1384 MEDIUM
Amazon Fire OS < 6.2.9.5 - Cross-Site Scripting via setMediaSource Function
CVSS 4.3
CVE-2023-22309 MEDIUM
Tribe29 Checkmk Appliance <1.6.4 - XSS
CVSS 6.1
CVE-2023-29508 HIGH
XWiki < 13.10.11 - Stored Cross-Site Scripting via Live Data Macro
CVSS 8.9
CVE-2023-29112 LOW
SAP Application Interface (Message Monitoring) -600,700 - XSS
CVSS 3.7
CVE-2023-29110 LOW
SAP ABAP Platform - Cross-Site Scripting via HTML Tag Injection
CVSS 3.7
CVE-2023-28851 MEDIUM
Silverstripe Form Capture <3.1.1 - XSS
CVSS 6.1
CVE-2023-1013 MEDIUM
Vira-Investing < 1.0.84.86 - Cross-Site Scripting
CVSS 6.1
CVE-2023-26047 MEDIUM
kitabisa/teler-waf < 0.2.0 - Cross-Site Scripting via Hex Entity Bypass
CVSS 6.5
CVE-2023-26046 MEDIUM
kitabisa/teler-waf < 0.1.1 - Cross-Site Scripting via HTML Entity Bypass
CVSS 6.5
CVE-2023-22464 MEDIUM
ViewVC < 1.1.30 and < 1.2.3 - Authenticated Cross-Site Scripting via Unsafe Filename Rendering
CVSS 5.4
CVE-2023-22461 HIGH
sanitize-svg < 0.4.0 - Cross-Site Scripting via Incomplete Deny-List Pattern
CVSS 7.6
CVE-2022-20654 MEDIUM
Cisco Webex Meetings - Unauthenticated Stored Cross-Site Scripting
CVSS 6.1
CVE-2022-38055 MEDIUM
wpForo Forum < 2.0.9 - Cross-Site Scripting
CVSS 4.3
CVE-2022-35850 MEDIUM
FortiAuthenticator 6.1.0-6.3.3 - Unauthenticated Reflected Cross-Site Scripting via Reset-Password Page
CVSS 4.3
CVE-2022-1274 MEDIUM
Keycloak < 20.0.5 - Cross-Site Scripting via Execute-Actions-Email Endpoint
CVSS 5.4
CVE-2022-38210 MEDIUM
Esri Portal for ArcGIS <10.9.1 - XSS
CVSS 6.1
CVE-2022-23543 MEDIUM
silverwaregames < 1.1.34 - Stored Cross-Site Scripting via Custom HTML Attributes in YouTube Iframe
CVSS 6.3
CVE-2022-28703 MEDIUM
Lansweeper 10.1.1.0 - Stored Cross-Site Scripting in HdConfigActions.aspx altertextlanguages
CVSS 5.4
CVE-2022-46350 MEDIUM
SCALANCE X204RNA - XSS
CVSS 6.1
CVE-2022-39372 LOW
GLPI 0.70-10.0.3 - Authenticated Stored Cross-Site Scripting in Account Information
CVSS 3.5
CVE-2022-39371 HIGH
GLPI 10.0.0-10.0.3 - Stored Cross-Site Scripting in Assets Inventory Information
CVSS 7.5
CVE-2022-39277 MEDIUM
GLPI 0.60-10.0.3 - Cross-Site Scripting via External Link Sanitization Bypass
CVSS 4.5
CVE-2022-3844 LOW
Webmin 2.001 - Cross-Site Scripting in xterm/index.cgi
CVSS 3.5
CVE-2022-39348 MEDIUM
Twisted 0.9.4-22.10.0rc1 - Cross-Site Scripting via Host Header in NameVirtualHost
CVSS 5.4
CVE-2022-39301 HIGH
sra-admin < 1.1.1 - Authenticated Stored Cross-Site Scripting via Profile Picture Upload
CVSS 8.2
Details
Vulnerabilities 538
Exploit Likelihood High