Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

566 CVEs tagged with CWE-8018 Critical, 86 High, 380 Medium, 80 Low, 2 Unrated.

CVE-2025-29427

Published Mar 17, 2025

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-29430

Published Mar 17, 2025

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-13497

Published Mar 15, 2025

The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25363

Published Mar 13, 2025

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with A…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-34398

Published Mar 12, 2025

An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27155

Published Mar 4, 2025

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-27099

Published Mar 3, 2025

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semanti…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-1807

Published Mar 2, 2025

A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknown part of the file /directRouter.rfc of the component Edit…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-22274

Published Feb 28, 2025

It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager i…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
20.4

CVE-2025-25299

Published Feb 20, 2025

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEdi…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
23.9

CVE-2023-51308

Published Feb 20, 2025

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" param…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13704

Published Feb 18, 2025

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insuf…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46910

Published Feb 13, 2025

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22402

Published Feb 7, 2025

Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privil…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38318

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim'…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-57004

Published Feb 3, 2025

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11954

Published Jan 28, 2025

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulatio…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24680

Published Jan 27, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Reflected XSS.This…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-35112

Published Jan 25, 2025

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24678

Published Jan 24, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in listamester Listamester listamester allows Stored XSS.This issue affects Listamester…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-24673

Published Jan 24, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ketchup Shortcodes ketchup-shortcodes-pack allows Stored XSS.This issue affe…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-23919

Published Jan 16, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Ella Van Durpe Slides & Presentations slide allows Code Injection.This issue affects…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Showing 226-250 of 566 CVEsPage 10 of 23