Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

559 CVEs tagged with CWE-8016 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2024-54223

Published Dec 9, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms Form Builder arforms-form-builder allows Code Injection.Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47869

Published Dec 9, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: fr…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-54128

Published Dec 5, 2024

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, s…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54001

Published Dec 5, 2024

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_langu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11479

Published Dec 4, 2024

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments of tickets, which…

CVSS 5.1 · Medium

CVE-2024-52598

Published Nov 20, 2024

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52597

Published Nov 20, 2024

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11404

Published Nov 20, 2024

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer…

CVSS 5.5 · Medium

CVE-2020-26067

Published Nov 18, 2024

A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is d…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10592

Published Nov 16, 2024

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient…

CVSS 6.4 · Medium

CVE-2022-20654

Published Nov 15, 2024

A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52300

Published Nov 13, 2024

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10038

Published Nov 13, 2024

The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient input sanitizat…

CVSS 6.1 · Medium

CVE-2024-51689

Published Nov 9, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler allows Reflected XSS.This issue a…

CVSS 7.1 · High

CVE-2024-10621

Published Nov 8, 2024

The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.…

CVSS 6.4 · Medium

CVE-2024-51735

Published Nov 5, 2024

Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be…

CVSS 8.7 · High

CVE-2024-49377

Published Nov 5, 2024

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9147

Published Nov 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings. This issue affects…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50344

Published Oct 30, 2024

I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunatel…

CVSS 4.6 · Medium

CVE-2024-9438

Published Oct 29, 2024

The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter in all versions up to, and including, 2.2.11 due to insuff…

CVSS 6.1 · Medium
Showing 251-275 of 559 CVEsPage 11 of 23