CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

538 vulnerabilities with CWE-80
CVE-2026-26460 MEDIUM
Vtiger CRM 8.4.0 - HTML Injection in Dashboard Tab Parameter
CVSS 6.1
CVE-2026-33657 MEDIUM
EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field
CVSS 4.6
CVE-2026-39941 MEDIUM
ChurchCRM <7.1.0 EditEventAttendees.php - Cross-Site Scripting
CVSS 6.1
CVE-2026-34718 MEDIUM
Zammad improperly neutralizes of script-related HTML tags in ticket articles
CVSS 6.1
CVE-2026-39712 MEDIUM
WordPress tagDiv Composer plugin <= 5.4.3 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39629 MEDIUM
WordPress Uminex theme <= 1.0.9 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39628 MEDIUM
WordPress DukaMarket theme <= 1.3.0 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39626 MEDIUM
WordPress Armania theme <= 1.4.8 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39625 MEDIUM
WordPress TechOne theme <= 3.0.3 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39841 MEDIUM
Stored XSS through list fields on Cargo's page values and Special:CargoTables
CVSS 6.1
CVE-2026-39839 MEDIUM
Stored XSS through URLs in Cargo's map format
CVSS 6.1
CVE-2026-39837 MEDIUM
Stored XSS through the dynamic table format in Cargo
CVSS 5.4
CVE-2026-39344 HIGH
Reflected XSS the login page through the 'username' parameter
CVSS 8.1
CVE-2026-35460 MEDIUM
Papra <26.4.0 Transactional Emails - HTML Injection
CVSS 4.3
CVE-2026-0396 LOW
HTML injection in the web dashboard
CVSS 3.1
CVE-2026-1834 MEDIUM
Ibtana - WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVSS 6.4
CVE-2026-2995 HIGH
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
CVSS 7.7
CVE-2026-33080 HIGH
Filament Tables 4.x and 5.x - Stored Cross-Site Scripting
CVSS 7.3
CVE-2026-32891 CRITICAL
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
CVSS 9.0
CVE-2026-29106 MEDIUM
SuiteCRM has blind XSS in return_id parameter
CVSS 5.9
CVE-2026-32753 HIGH
FreeScout: Stored XSS through SVG file upload with filter bypass
CVE-2026-27166 MEDIUM
Discourse vulnerable to HTML injection via prohibited iframe URLs
CVSS 4.1
CVE-2026-28499 MEDIUM
Vapor LeafKit < 1.14.2 - Collection Value Cross-Site Scripting
CVSS 6.1
CVE-2026-32732 NONE
@leanprover/unicode-input-component <0.2.0 - XSS
CVE-2026-20070 MEDIUM
Cisco Secure Firewall ASA and FTD - Unauthenticated Cross-Site Scripting via VPN Web Services
CVSS 6.1
Details
Vulnerabilities 538
Exploit Likelihood High