CWE-80
High likelihoodImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
538 vulnerabilities with CWE-80
CVE-2025-11267
MEDIUM
VK All in One Expansion Unit <9.112.1 - XSS
CVSS 6.4
CVE-2025-11265
MEDIUM
VK All in One Expansion Unit <9.112.1 - XSS
CVSS 6.4
CVE-2025-8386
MEDIUM
AVEVA Application Server - Authenticated XSS via App Objects Help Files
CVSS 6.9
CVE-2025-13180
LOW
Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System < 20250320 - Cross-Site Scripting
CVSS 3.5
CVE-2025-13178
LOW
Bdtask SalesERP < 2025-10-24 - Cross-Site Scripting via User Profile Handler
CVSS 3.5
CVE-2025-54348
MEDIUM
Desktop Alert PingAlert Application Server 6.1.0.11-6.1.1.2 - Stored Cross-Site Scripting
CVSS 6.5
CVE-2025-54346
HIGH
Desktop Alert PingAlert Application Server 6.1.0.11-6.1.1.2 - Reflected Cross-Site Scripting
CVSS 7.6
CVE-2025-12753
MEDIUM
Chart Expert <= 1.0 - Authenticated Stored Cross-Site Scripting via pmzez_chart Shortcode
CVSS 6.4
CVE-2025-11874
MEDIUM
Slippy Slider <= 2.0 - Authenticated Stored XSS via Shortcode Attributes
CVSS 5.4
CVE-2025-64187
MEDIUM
OctoPrint < 1.11.4 - Stored Cross-Site Scripting via Action Command Notifications
CVSS 4.4
CVE-2025-33110
MEDIUM
IBM OpenPages 9.0-9.1 - Cross-Site Scripting
CVSS 5.4
CVE-2025-60244
HIGH
RealMag777 TableOn <= 1.0.5.1 - Code Injection via Improper HTML Tag Neutralization
CVSS 7.1
CVE-2025-49398
MEDIUM
Easy Appointments <= 3.12.14 - Cross-Site Scripting
CVSS 6.5
CVE-2025-11745
MEDIUM
Ad Inserter - Ad Manager & AdSense Ads <2.8.7 - XSS
CVSS 6.4
CVE-2025-11987
MEDIUM
Visual Link Preview <= 2.2.7 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
CVSS 6.4
CVE-2025-48884
MEDIUM
Galette < 1.2.0 - Cross-Site Scripting in Document Type
CVSS 6.1
CVE-2025-53883
CRITICAL
Container suse/manager/5.0/x86_64/server:latest - Basic XSS
CVE-2025-39663
HIGH
Checkmk < 2.4.0p14, 2.3.0p39, 2.2.0, 2.1.0 - Cross-Site Scripting via Service Output Injection
CVSS 8.4
CVE-2025-62796
MEDIUM
PrivateBin 1.7.7-2.0.1 - Persistent HTML Injection via Attachment Filename
CVSS 5.8
CVE-2025-36121
MEDIUM
IBM OpenPages 9.0-9.1 - Authenticated HTML Injection
CVSS 5.4
CVE-2025-62936
MEDIUM
Jthemes xSmart <= 1.2.9.4 - Basic XSS
CVSS 4.3
CVE-2025-62897
MEDIUM
Brecht WP Recipe Maker <10.1.1 - Basic XSS
CVSS 5.3
CVE-2025-11823
MEDIUM
ShopLentor < 3.2.4 - Authenticated Stored Cross-Site Scripting via wishsuite_button Shortcode
CVSS 6.4
CVE-2025-11992
MEDIUM
Multi Item Responsive Slider <1.0 - CSRF
CVSS 6.1
CVE-2025-58970
MEDIUM
AmentoTech Doctreat <=1.6.7 - Code Injection
CVSS 6.3
Details
Vulnerabilities
538
Exploit Likelihood
High