CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
562 vulnerabilities with CWE-80
CVE-2026-39625
MEDIUM
WordPress TechOne theme <= 3.0.3 - Arbitrary Shortcode Execution vulnerability
CVSS 5.3
CVE-2026-39841
MEDIUM
Stored XSS through list fields on Cargo's page values and Special:CargoTables
CVSS 6.1
CVE-2026-39839
MEDIUM
Stored XSS through URLs in Cargo's map format
CVSS 6.1
CVE-2026-39837
MEDIUM
Stored XSS through the dynamic table format in Cargo
CVSS 5.4
CVE-2026-39344
HIGH
Reflected XSS the login page through the 'username' parameter
CVSS 8.1
CVE-2026-35460
MEDIUM
Papra <26.4.0 Transactional Emails - HTML Injection
CVSS 4.3
CVE-2026-0396
LOW
HTML injection in the web dashboard
CVSS 3.1
CVE-2026-1834
MEDIUM
Ibtana - WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVSS 6.4
CVE-2026-2995
HIGH
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
CVSS 7.7
CVE-2026-33080
HIGH
Filament Tables 4.x and 5.x - Stored Cross-Site Scripting
CVSS 7.3
CVE-2026-32891
CRITICAL
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
CVSS 9.0
CVE-2026-29106
MEDIUM
SuiteCRM has blind XSS in return_id parameter
CVSS 5.9
CVE-2026-32753
MEDIUM
FreeScout: Stored XSS through SVG file upload with filter bypass
CVSS 5.4
CVE-2026-27166
MEDIUM
Discourse vulnerable to HTML injection via prohibited iframe URLs
CVSS 4.1
CVE-2026-28499
MEDIUM
Vapor LeafKit < 1.14.2 - Collection Value Cross-Site Scripting
CVSS 6.1
CVE-2026-32732
NONE
@leanprover/unicode-input-component <0.2.0 - XSS
CVE-2026-20070
MEDIUM
Cisco Secure Firewall ASA and FTD - Unauthenticated Cross-Site Scripting via VPN Web Services
CVSS 6.1
CVE-2026-28132
MEDIUM
WooCommerce Photo Reviews <=1.4.4 - XSS
CVSS 5.3
CVE-2026-27578
MEDIUM
n8n <2.10.1/2.9.3/1.123.22 - XSS
CVSS 5.4
CVE-2026-27116
MEDIUM
vikunja/vikunja < 2.0.0 - Reflected HTML Injection via Projects Filter Parameter
CVSS 6.1
CVE-2026-27458
MEDIUM
LinkAce < 2.4.3 - Authenticated Stored Cross-Site Scripting via List Description in Atom Feed
CVSS 5.4
CVE-2026-25006
MEDIUM
XStore <= 9.6.4 - Code Injection via Improper Neutralization of Script-Related HTML Tags
CVSS 5.3
CVE-2026-22422
MEDIUM
Everest Forms <= 3.4.1 - Code Injection via Improper Neutralization of Script-Related HTML Tags
CVSS 5.3
CVE-2026-25935
MEDIUM
vikunja/vikunja < 1.1.0 - Stored Cross-Site Scripting via Task Description Hover
CVSS 5.4
CVE-2026-1282
LOW
GitLab 18.6.0-18.6.5, 18.7.0-18.7.3, 18.8.0-18.8.3 - Authenticated Stored Cross-Site Scripting in Project Label Titles
CVSS 3.5
Details
Vulnerabilities
562
Exploit Likelihood
High