Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

561 CVEs tagged with CWE-8018 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2024-58355

Published Jul 23, 2026

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders book…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2024-58353

Published Jul 23, 2026

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-32822

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54443

Published Jul 15, 2026

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rende…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-59838

Published Jul 15, 2026

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57167

Published Jul 10, 2026

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages embed a schema.org JSON-LD block by JSON.stringify-ing video…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-59855

Published Jul 9, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assign…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-7380

Published Jul 7, 2026

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targ…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50229

Published Jun 29, 2026

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-64637

Published Jun 26, 2026

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57535

Published Jun 25, 2026

Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rende…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57534

Published Jun 25, 2026

Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57533

Published Jun 25, 2026

Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57532

Published Jun 25, 2026

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one back…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13314

Published Jun 25, 2026

Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-13225

Published Jun 25, 2026

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that ord…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-52816

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST /-/api/sanitize_ipynb allows arbitrary data: URIs without…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-50146

Published Jun 22, 2026

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping t…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62198

Published Jun 22, 2026

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-12812

Published Jun 21, 2026

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation leads…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1

CVE-2025-71331

Published Jun 20, 2026

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-46492

Published Jun 9, 2026

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown ren…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-34033

Published Jun 9, 2026

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied cont…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-11511

Published Jun 8, 2026

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Han…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1
Showing 1-25 of 561 CVEsPage 1 of 23