CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

517 vulnerabilities with CWE-80
CVE-2025-20342 MEDIUM
Cisco IMC - XSS
CVSS 5.4
CVE-2025-6247 MEDIUM
WordPress Automatic Plugin <3.118.0 - CSRF
CVSS 4.7
CVE-2025-51989 HIGH
Evolution Consulting Kft. HRmaster <v235 - Code Injection
CVSS 7.0
CVE-2025-57730 MEDIUM
Jetbrains Intellij Idea < 2025.2.0 - Basic XSS
CVSS 5.2
CVE-2025-55291 HIGH
Shaarli <0.15.0 - XSS
CVSS 7.1
CVE-2025-54421 HIGH
Nameless < 2.2.4 - Basic XSS
CVSS 7.2
CVE-2025-54117 CRITICAL
Nameless < 2.2.4 - Basic XSS
CVSS 9.0
CVE-2025-55672 MEDIUM
Apache Superset <5.0.0 - XSS
CVSS 5.4
CVE-2025-54698 MEDIUM
RadiusTheme Classified Listing <5.0.0 - Basic XSS
CVSS 5.4
CVE-2025-8621 MEDIUM
Mosaic Generator <1.0.5 - XSS
CVSS 6.4
CVE-2025-20331 MEDIUM
Cisco ISE - Stored XSS
CVSS 5.4
CVE-2025-54789 MEDIUM
Humhub Files < 0.16.10 - Basic XSS
CVSS 6.1
CVE-2025-54589 MEDIUM
9001 Copyparty < 1.18.7 - Basic XSS
CVSS 6.3
CVE-2025-52897 MEDIUM
Glpi < 10.0.19 - Basic XSS
CVSS 6.5
CVE-2025-27514 MEDIUM
GLPI <10.0.18 - Stored XSS
CVSS 4.5
CVE-2025-54414 MEDIUM
Anubis <1.21.2 - XSS
CVE-2025-8029 HIGH
Mozilla Firefox < 128.13.0 - Basic XSS
CVSS 8.1
CVE-2025-53835 CRITICAL
XWiki Rendering <14.10 - XSS
CVSS 9.0
CVE-2025-31326 MEDIUM
SAP BusinessObjects - HTML Injection
CVSS 4.1
CVE-2025-27358 MEDIUM
N-Media Frontend File Manager <23.2 - XSS
CVSS 4.6
CVE-2025-2895 MEDIUM
IBM Cloud Pak System - Basic XSS
CVSS 5.4
CVE-2025-53093 HIGH
Starcitizentools Tabber-neue < 3.1.1 - Basic XSS
CVSS 8.6
CVE-2025-52902 HIGH
Filebrowser < 2.33.7 - Basic XSS
CVSS 7.6
CVE-2025-4367 MEDIUM
W3eden Download Manager < 3.3.19 - Basic XSS
CVSS 6.4
CVE-2025-4278 HIGH
GitLab CE/EE <18.0.2 - XSS
CVSS 8.7
Details
Vulnerabilities 517
Exploit Likelihood High