Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

559 CVEs tagged with CWE-8016 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2025-11161

Published Oct 15, 2025

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This i…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11160

Published Oct 15, 2025

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62172

Published Oct 14, 2025

Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to sto…

CVSS 8.5 · High

CVE-2025-31992

Published Oct 12, 2025

HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user'…

CVSS 4.6 · Medium

CVE-2025-10496

Published Oct 9, 2025

The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficien…

CVSS 7.2 · High
evidence mentions
5
Buzz score
27.9

CVE-2025-52654

Published Oct 3, 2025

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized c…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11241

Published Oct 3, 2025

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content,…

CVSS 6.4 · Medium

CVE-2025-61583

Published Oct 1, 2025

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulne…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58054

Published Oct 1, 2025

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-10128

Published Sep 30, 2025

The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' shortcode in all versions up to, and including, 4.0.1 due t…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-60100

Published Sep 26, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a throu…

CVSS 5.3 · Medium

CVE-2025-59573

Published Sep 22, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CozyThemes Cozy Blocks cozy-addons allows Code Injection.This issue affects Cozy Blo…

CVSS 5.3 · Medium

CVE-2025-57928

Published Sep 22, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Code Inj…

CVSS 5.3 · Medium

CVE-2025-10125

Published Sep 17, 2025

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insu…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-58430

Published Sep 9, 2025

listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-20342

Published Aug 27, 2025

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with…

CVSS 5.4 · Medium

CVE-2025-6247

Published Aug 26, 2025

The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect…

CVSS 4.7 · Medium

CVE-2025-51989

Published Aug 21, 2025

HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstnam…

CVSS 7.0 · High

CVE-2025-55291

Published Aug 18, 2025

Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag…

CVSS 7.1 · High

CVE-2025-54421

Published Aug 18, 2025

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticate…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54117

Published Aug 18, 2025

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticate…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55672

Published Aug 14, 2025

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious pay…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 559 CVEsPage 7 of 23