Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

564 CVEs tagged with CWE-8018 Critical, 86 High, 378 Medium, 80 Low, 2 Unrated.

CVE-2025-5686

Published Jun 6, 2025

The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insuffici…

CVSS 6.4 · Medium

CVE-2025-23393

Published May 27, 2025

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows execution of arbitrary Javascript code on users machines.Th…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-23392

Published May 26, 2025

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.Thi…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-33138

Published May 22, 2025

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's We…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20267

Published May 21, 2025

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) a…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-51475

Published May 16, 2025

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the vi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4126

Published May 15, 2025

The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due to insufficient…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-4168

Published May 3, 2025

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insuffi…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-3521

Published May 1, 2025

The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social Link icon…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-39524

Published Apr 16, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-32027

Published Apr 10, 2025

Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiiso…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-32230

Published Apr 10, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 3.4.0.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-31384

Published Apr 4, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-30676

Published Apr 1, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommen…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2025-30210

Published Apr 1, 2025

Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this ca…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-30161

Published Mar 31, 2025

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR all…

CVSS 8.4 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-31604

Published Mar 31, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com cal-com allows Stored XSS.This issue affects Cal.com: from n/a throu…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-31575

Published Mar 31, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vasilis Triantafyllou Flag Icons language-icons-flags-switcher allows Stored XSS.Thi…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-22501

Published Mar 28, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Improve My City Improve My City improve-my-city allows Reflected XSS.This issue affe…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-31075

Published Mar 28, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments paid-membership allows Stored XSS.This issue affects Micr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-1997

Published Mar 27, 2025

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-29427

Published Mar 17, 2025

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-29430

Published Mar 17, 2025

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 201-225 of 564 CVEsPage 9 of 23