CWE-80

High likelihood

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Parent: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

563 vulnerabilities with CWE-80
CVE-2025-4168 MEDIUM
Subpage List <= 1.3.3 - Authenticated Stored Cross-Site Scripting via 'subpages' Shortcode
CVSS 6.4
CVE-2025-3521 MEDIUM
Team Members - WordPress <3.4.0 - XSS
CVSS 6.4
CVE-2025-39524 MEDIUM
bPlugins Html5 Audio Player <2.2.28 - XSS
CVSS 6.5
CVE-2025-32027 MEDIUM
Yii < 1.1.31 - Reflected Cross-Site Scripting via Fallback Error Renderer
CVSS 6.1
CVE-2025-32230 MEDIUM
Tutor LMS < 3.4.0 - Stored Cross-Site Scripting
CVSS 4.3
CVE-2025-31384 HIGH
Aviplugins Videos < 1.0.5 - Reflected Cross-Site Scripting
CVSS 7.1
CVE-2025-0272 MEDIUM
HCL DevOps Deploy 8.0.0.0-8.0.1.4 and HCL Launch 7.0.0.0-7.0.5.25 - HTML Injection in Web UI
CVSS 5.4
CVE-2025-30676 MEDIUM
Apache OFBiz < 18.12.19 - Cross-Site Scripting
CVSS 6.1
CVE-2025-30210 MEDIUM
Bruno < 1.39.1 - Stored Cross-Site Scripting via Environment Name Tooltip
CVSS 6.1
CVE-2025-30161 MEDIUM
OpenEMR < 7.0.3 - Stored Cross-Site Scripting in Bronchitis Form
CVSS 5.4
CVE-2025-31604 MEDIUM
Cal.com <= 1.0.0 - Stored Cross-Site Scripting
CVSS 6.5
CVE-2025-31575 MEDIUM
Flag Icons <= 2.2 - Stored Cross-Site Scripting
CVSS 5.9
CVE-2025-22501 HIGH
Improve My City <= 1.6 - Reflected Cross-Site Scripting
CVSS 7.1
CVE-2025-31075 MEDIUM
videowhisper MicroPayments <2.9.29 - XSS
CVSS 6.5
CVE-2025-1997 MEDIUM
IBM UrbanCode Deploy/DevOps Deploy <7.3.2.0 - XSS
CVSS 5.4
CVE-2025-29426 MEDIUM
Code-projects Online Class and Exam Scheduling System V1.0 - Cross-Site Scripting via id and cys Parameters
CVSS 4.6
CVE-2025-29427 MEDIUM
Online Class and Exam Scheduling System 1.0 - Cross-Site Scripting via member_first and member_last Parameters
CVSS 5.9
CVE-2025-29430 MEDIUM
Online Class and Exam Scheduling System V1.0 - Cross-Site Scripting via id and rome Parameters
CVSS 4.1
CVE-2025-29431 LOW
Code-projects Online Class and Exam Scheduling System V1.0 - Cross-Site Scripting via id, code, and name Parameters
CVSS 3.2
CVE-2025-25363 MEDIUM
Thepluginpeople Enterprise Mail Handler < 4.1.69-dc - Basic XSS
CVSS 6.5
CVE-2025-28015 MEDIUM
PHPGurukul User Registration & Login and User Management System V3.3 - Cross-Site Scripting via Edit Profile Parameters
CVSS 5.3
CVE-2025-27155 MEDIUM
Pinecone < 218b2801995b174085cb1c8fafe2d3aa661f85bd - Stored Cross-Site Scripting
CVSS 6.1
CVE-2025-27099 MEDIUM
Tuleap < 16.3-10 and < 16.4.99.1740067916 - Cross-Site Scripting via Tracker Name in Semantic Timeframe Deletion Message
CVSS 4.8
CVE-2025-1807 LOW
Eastnets PaymentSafe <2.5.26.0 - XSS
CVSS 3.5
CVE-2025-22274 LOW
CyberArk Endpoint Privilege Manager <24.7.1 - XSS
Details
Vulnerabilities 563
Exploit Likelihood High