CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
562 vulnerabilities with CWE-80
CVE-2026-25764
LOW
OpenProject < 16.6.7 - Authenticated HTML Injection in Time Tracking Work Package Name
CVSS 3.5
CVE-2026-22254
NONE
Winter CMS < 1.2.10 - Authenticated Stored Cross-Site Scripting via SVG Upload
CVE-2026-25578
MEDIUM
navidrome < 0.60.0 - Stored Cross-Site Scripting via Song Comment Metadata
CVSS 6.1
CVE-2026-25054
MEDIUM
n8n < 1.123.9 and 2.0.0-2.2.1 - Authenticated Stored Cross-Site Scripting in Markdown Renderer
CVSS 5.4
CVE-2026-24128
MEDIUM
XWiki Platform 7.0-milestone-2-16.10.11, 17.0.0-rc-1-17.4.4, 17.5.0-rc-1-17.7.0 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2026-24564
MEDIUM
Israpil Textmetrics <3.6.3 - Code Injection
CVSS 4.3
CVE-2026-22469
MEDIUM
DeepDigital <= 1.0.2 - Code Injection via Arbitrary Shortcode Execution
CVSS 5.3
CVE-2026-1154
MEDIUM
SourceCodester E-Learning System 1.0 - Cross-Site Scripting via Lesson Module Title/Description
CVSS 4.3
CVE-2026-23528
MEDIUM
Dask distributed < 2026.1.0 - Cross-Site Scripting via Jupyter Lab Dashboard Proxy
CVSS 6.1
CVE-2026-20047
MEDIUM
Cisco Identity Services Engine - Authenticated Stored Cross-Site Scripting in Web Management Interface
CVSS 4.8
CVE-2025-36321
MEDIUM
Vulnerabilities found in Watson Data Intelligence
CVSS 5.7
CVE-2025-64637
MEDIUM
WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability
CVSS 5.3
CVE-2025-62198
MEDIUM
Apache Atlas: Stored XSS in Create Entity page
CVSS 5.4
CVE-2025-71331
MEDIUM
Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
CVSS 6.1
CVE-2025-71310
LOW
Backdropcms Gdpr Cookies Module For Backdrop Cms < 1.x-1.3.5 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2025-15345
MEDIUM
MapGeo - Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter
CVSS 6.1
CVE-2025-59854
LOW
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability
CVSS 3.1
CVE-2025-66486
MEDIUM
IBM Aspera Shares 1.9.9-1.11.0 - HTML Injection
CVSS 4.8
CVE-2025-59540
MEDIUM
Chamilo LMS < 1.11.34 - Stored Cross-Site Scripting in Exercise History Feedback
CVSS 5.4
CVE-2025-52564
MEDIUM
Chamilo LMS < 1.11.30 - Cross-Site Scripting via help.php Open Parameter
CVSS 6.1
CVE-2025-52563
MEDIUM
Chamilo LMS < 1.11.30 - Reflected Cross-Site Scripting via Page Parameter
CVSS 6.1
CVE-2025-14289
MEDIUM
IBM webMethods Integration Server 12.0 - XSS
CVSS 5.4
CVE-2025-12803
MEDIUM
Bold Page Builder <= 5.5.1 - Authenticated Stored Cross-Site Scripting via bt_bb_tabs Shortcode
CVSS 6.4
CVE-2025-65924
MEDIUM
ERPNext <= 15.88.1 - HTML Injection in Add Quality Goal Function
CVSS 4.1
CVE-2025-45160
MEDIUM
Cacti <= 1.2.29 - HTML Injection via File Upload Error Popup
CVSS 5.4
Details
Vulnerabilities
562
Exploit Likelihood
High