Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

559 CVEs tagged with CWE-8016 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2025-54698

Published Aug 14, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue a…

CVSS 5.4 · Medium

CVE-2025-8621

Published Aug 12, 2025

The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all versions up to, and including, 1.0.5 due to insufficient input…

CVSS 6.4 · Medium

CVE-2025-20331

Published Aug 6, 2025

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of…

CVSS 5.4 · Medium

CVE-2025-54789

Published Aug 2, 2025

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54589

Published Jul 31, 2025

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52897

Published Jul 30, 2025

GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27514

Published Jul 29, 2025

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a t…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49343

Published Jul 28, 2025

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54414

Published Jul 26, 2025

Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources from scraper bots. In versions 1…

CVSS 5.1 · Medium

CVE-2025-8029

Published Jul 22, 2025

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53835

Published Jul 14, 2025

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31326

Published Jul 8, 2025

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code int…

CVSS 4.1 · Medium

CVE-2025-27358

Published Jul 4, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This i…

CVSS 4.6 · Medium

CVE-2025-2895

Published Jun 30, 2025

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject malicious H…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53093

Published Jun 27, 2025

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by in…

CVSS 8.6 · High

CVE-2023-38007

Published Jun 27, 2025

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to HTML injectio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52902

Published Jun 26, 2025

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4367

Published Jun 19, 2025

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4278

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to acco…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5686

Published Jun 6, 2025

The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insuffici…

CVSS 6.4 · Medium

CVE-2025-23393

Published May 27, 2025

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows execution of arbitrary Javascript code on users machines.Th…

CVSS 5.6 · Medium

CVE-2025-23392

Published May 26, 2025

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.Thi…

CVSS 5.6 · Medium

CVE-2025-33138

Published May 22, 2025

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's We…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20267

Published May 21, 2025

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) a…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 559 CVEsPage 8 of 23