CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
538 vulnerabilities with CWE-80
CVE-2025-14289
MEDIUM
IBM webMethods Integration Server 12.0 - XSS
CVSS 5.4
CVE-2025-12803
MEDIUM
Bold Page Builder <= 5.5.1 - Authenticated Stored Cross-Site Scripting via bt_bb_tabs Shortcode
CVSS 6.4
CVE-2025-65924
MEDIUM
ERPNext <= 15.88.1 - HTML Injection in Add Quality Goal Function
CVSS 4.1
CVE-2025-45160
MEDIUM
Cacti <= 1.2.29 - HTML Injection via File Upload Error Popup
CVSS 5.4
CVE-2025-47600
MEDIUM
xtemos WoodMart <=8.3.7 - Code Injection
CVSS 5.3
CVE-2025-36397
MEDIUM
IBM Application Gateway 23.10-25.09 - HTML Injection
CVSS 5.4
CVE-2025-69169
MEDIUM
Noor Alam Easy Media Download <1.1.11 - Basic XSS
CVSS 5.4
CVE-2025-15058
MEDIUM
Responsive Pricing Table plugin <5.1.12 - XSS
CVSS 6.4
CVE-2025-14835
HIGH
WP Photo Album Plus <9.1.05.008 - XSS
CVSS 7.1
CVE-2025-14792
MEDIUM
Key Figures <= 1.1 - Authenticated Stored Cross-Site Scripting via kf_field_figure_default_color_render
CVSS 4.4
CVE-2025-45286
MEDIUM
go-httpbin < 2.18.0 - Cross-Site Scripting via Crafted Payload
CVSS 6.1
CVE-2025-36230
MEDIUM
IBM Aspera Faspex 5.0.0-5.0.14.1 - HTML Injection
CVSS 5.4
CVE-2025-14735
MEDIUM
Amazon affiliate lite Plugin <1.0.0 - XSS
CVSS 4.4
CVE-2025-64225
MEDIUM
colabrio Stockie Extra <=1.2.11 - XSS
CVSS 6.5
CVE-2025-64633
MEDIUM
colabrio Norebro Extra <=1.6.8 - Basic XSS
CVSS 5.3
CVE-2025-66450
MEDIUM
LibreChat < 0.8.1 - Stored Cross-Site Scripting via IconURL Parameter
CVSS 5.4
CVE-2025-66472
MEDIUM
XWiki Platform <16.10.9, <17.0.0-rc-1 to <17.4.1 - XSS
CVSS 6.1
CVE-2025-63068
MEDIUM
Contact Form 7 Dynamic Text Extension <5.0.3 - XSS
CVSS 5.3
CVE-2025-66481
CRITICAL
deepchat < 0.5.1 - Stored Cross-Site Scripting via Mermaid Content Bypass
CVSS 9.6
CVE-2025-14186
LOW
Grandstream GXP1625 1.0.7.4 - Cross-Site Scripting via vpn_ip Parameter
CVSS 3.5
CVE-2025-66512
MEDIUM
Nextcloud Server <31.0.12-32.0.3 - Info Disclosure
CVSS 5.4
CVE-2025-13505
MEDIUM
Datactive 2.13.34-2.14.0.5 - Stored Cross-Site Scripting
CVSS 4.8
CVE-2025-54057
MEDIUM
Apache SkyWalking <= 10.2.0 - Cross-Site Scripting
CVSS 6.1
CVE-2025-64764
HIGH
Astro < 5.15.8 - Reflected Cross-Site Scripting via Server Islands Feature
CVSS 7.1
CVE-2025-58412
MEDIUM
Fortinet FortiADC 7.2.0-7.6.3, 8.0.0 - Cross-Site Scripting via Crafted URL
CVSS 4.7
Details
Vulnerabilities
538
Exploit Likelihood
High