CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

538 vulnerabilities with CWE-80
CVE-2025-14289 MEDIUM
IBM webMethods Integration Server 12.0 - XSS
CVSS 5.4
CVE-2025-12803 MEDIUM
Bold Page Builder <= 5.5.1 - Authenticated Stored Cross-Site Scripting via bt_bb_tabs Shortcode
CVSS 6.4
CVE-2025-65924 MEDIUM
ERPNext <= 15.88.1 - HTML Injection in Add Quality Goal Function
CVSS 4.1
CVE-2025-45160 MEDIUM
Cacti <= 1.2.29 - HTML Injection via File Upload Error Popup
CVSS 5.4
CVE-2025-47600 MEDIUM
xtemos WoodMart <=8.3.7 - Code Injection
CVSS 5.3
CVE-2025-36397 MEDIUM
IBM Application Gateway 23.10-25.09 - HTML Injection
CVSS 5.4
CVE-2025-69169 MEDIUM
Noor Alam Easy Media Download <1.1.11 - Basic XSS
CVSS 5.4
CVE-2025-15058 MEDIUM
Responsive Pricing Table plugin <5.1.12 - XSS
CVSS 6.4
CVE-2025-14835 HIGH
WP Photo Album Plus <9.1.05.008 - XSS
CVSS 7.1
CVE-2025-14792 MEDIUM
Key Figures <= 1.1 - Authenticated Stored Cross-Site Scripting via kf_field_figure_default_color_render
CVSS 4.4
CVE-2025-45286 MEDIUM
go-httpbin < 2.18.0 - Cross-Site Scripting via Crafted Payload
CVSS 6.1
CVE-2025-36230 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.14.1 - HTML Injection
CVSS 5.4
CVE-2025-14735 MEDIUM
Amazon affiliate lite Plugin <1.0.0 - XSS
CVSS 4.4
CVE-2025-64225 MEDIUM
colabrio Stockie Extra <=1.2.11 - XSS
CVSS 6.5
CVE-2025-64633 MEDIUM
colabrio Norebro Extra <=1.6.8 - Basic XSS
CVSS 5.3
CVE-2025-66450 MEDIUM
LibreChat < 0.8.1 - Stored Cross-Site Scripting via IconURL Parameter
CVSS 5.4
CVE-2025-66472 MEDIUM
XWiki Platform <16.10.9, <17.0.0-rc-1 to <17.4.1 - XSS
CVSS 6.1
CVE-2025-63068 MEDIUM
Contact Form 7 Dynamic Text Extension <5.0.3 - XSS
CVSS 5.3
CVE-2025-66481 CRITICAL
deepchat < 0.5.1 - Stored Cross-Site Scripting via Mermaid Content Bypass
CVSS 9.6
CVE-2025-14186 LOW
Grandstream GXP1625 1.0.7.4 - Cross-Site Scripting via vpn_ip Parameter
CVSS 3.5
CVE-2025-66512 MEDIUM
Nextcloud Server <31.0.12-32.0.3 - Info Disclosure
CVSS 5.4
CVE-2025-13505 MEDIUM
Datactive 2.13.34-2.14.0.5 - Stored Cross-Site Scripting
CVSS 4.8
CVE-2025-54057 MEDIUM
Apache SkyWalking <= 10.2.0 - Cross-Site Scripting
CVSS 6.1
CVE-2025-64764 HIGH
Astro < 5.15.8 - Reflected Cross-Site Scripting via Server Islands Feature
CVSS 7.1
CVE-2025-58412 MEDIUM
Fortinet FortiADC 7.2.0-7.6.3, 8.0.0 - Cross-Site Scripting via Crafted URL
CVSS 4.7
Details
Vulnerabilities 538
Exploit Likelihood High