Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

561 CVEs tagged with CWE-8018 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2023-46310

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45635

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: f…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-45053

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in pluginever WP Content Pilot – Autoblogging & Affiliate Marketing Plugin allows Code…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-40557

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accordion allows Code Injection.This issue affects Tabs & Accordi…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-39161

Published Jun 4, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-23735

Published Jun 3, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35224

Published May 23, 2024

OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4214

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a…

CVSS 2.7 · Low

CVE-2024-32790

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricin…

CVSS 4.3 · Medium

CVE-2024-24874

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a thro…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23522

Published May 17, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34699

Published May 14, 2024

GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This probl…

CVSS 6.5 · Medium

CVE-2024-34070

Published May 14, 2024

Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging…

CVSS 9.6 · Critical

CVE-2024-34507

Published May 5, 2024

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishand…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4439

Published May 3, 2024

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the d…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-33423

Published May 1, 2024

Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the L…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32966

Published May 1, 2024

Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a d…

CVSS 5.8 · Medium

CVE-2024-33831

Published Apr 30, 2024

A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a cra…

CVSS 7.4 · High

CVE-2023-48763

Published Apr 24, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: fr…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-32875

Published Apr 23, 2024

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. H…

CVSS 6.1 · Medium

CVE-2024-32472

Published Apr 17, 2024

excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run i…

CVSS 6.1 · Medium

CVE-2024-32746

Published Apr 17, 2024

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44396

Published Apr 15, 2024

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43790

Published Apr 15, 2024

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerabil…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 561 CVEsPage 14 of 23