CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

538 vulnerabilities with CWE-80
CVE-2025-11267 MEDIUM
VK All in One Expansion Unit <9.112.1 - XSS
CVSS 6.4
CVE-2025-11265 MEDIUM
VK All in One Expansion Unit <9.112.1 - XSS
CVSS 6.4
CVE-2025-8386 MEDIUM
AVEVA Application Server - Authenticated XSS via App Objects Help Files
CVSS 6.9
CVE-2025-13180 LOW
Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System < 20250320 - Cross-Site Scripting
CVSS 3.5
CVE-2025-13178 LOW
Bdtask SalesERP < 2025-10-24 - Cross-Site Scripting via User Profile Handler
CVSS 3.5
CVE-2025-54348 MEDIUM
Desktop Alert PingAlert Application Server 6.1.0.11-6.1.1.2 - Stored Cross-Site Scripting
CVSS 6.5
CVE-2025-54346 HIGH
Desktop Alert PingAlert Application Server 6.1.0.11-6.1.1.2 - Reflected Cross-Site Scripting
CVSS 7.6
CVE-2025-12753 MEDIUM
Chart Expert <= 1.0 - Authenticated Stored Cross-Site Scripting via pmzez_chart Shortcode
CVSS 6.4
CVE-2025-11874 MEDIUM
Slippy Slider <= 2.0 - Authenticated Stored XSS via Shortcode Attributes
CVSS 5.4
CVE-2025-64187 MEDIUM
OctoPrint < 1.11.4 - Stored Cross-Site Scripting via Action Command Notifications
CVSS 4.4
CVE-2025-33110 MEDIUM
IBM OpenPages 9.0-9.1 - Cross-Site Scripting
CVSS 5.4
CVE-2025-60244 HIGH
RealMag777 TableOn <= 1.0.5.1 - Code Injection via Improper HTML Tag Neutralization
CVSS 7.1
CVE-2025-49398 MEDIUM
Easy Appointments <= 3.12.14 - Cross-Site Scripting
CVSS 6.5
CVE-2025-11745 MEDIUM
Ad Inserter - Ad Manager & AdSense Ads <2.8.7 - XSS
CVSS 6.4
CVE-2025-11987 MEDIUM
Visual Link Preview <= 2.2.7 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2025-48884 MEDIUM
Galette < 1.2.0 - Cross-Site Scripting in Document Type
CVSS 6.1
CVE-2025-53883 CRITICAL
Container suse/manager/5.0/x86_64/server:latest - Basic XSS
CVE-2025-39663 HIGH
Checkmk < 2.4.0p14, 2.3.0p39, 2.2.0, 2.1.0 - Cross-Site Scripting via Service Output Injection
CVSS 8.4
CVE-2025-62796 MEDIUM
PrivateBin 1.7.7-2.0.1 - Persistent HTML Injection via Attachment Filename
CVSS 5.8
CVE-2025-36121 MEDIUM
IBM OpenPages 9.0-9.1 - Authenticated HTML Injection
CVSS 5.4
CVE-2025-62936 MEDIUM
Jthemes xSmart <= 1.2.9.4 - Basic XSS
CVSS 4.3
CVE-2025-62897 MEDIUM
Brecht WP Recipe Maker <10.1.1 - Basic XSS
CVSS 5.3
CVE-2025-11823 MEDIUM
ShopLentor < 3.2.4 - Authenticated Stored Cross-Site Scripting via wishsuite_button Shortcode
CVSS 6.4
CVE-2025-11992 MEDIUM
Multi Item Responsive Slider <1.0 - CSRF
CVSS 6.1
CVE-2025-58970 MEDIUM
AmentoTech Doctreat <=1.6.7 - Code Injection
CVSS 6.3
Details
Vulnerabilities 538
Exploit Likelihood High