Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-80

2
CRITICAL
13
HIGH
95
MEDIUM
6
LOW
137 CVEs · Page 1/3
9.0
CVE-2026-32891

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media

8.9
CVE-2024-58353

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac

8.9
CVE-2024-58355

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking

8.8
CVE-2026-6002

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te

8.6
CVE-2026-52854

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers

8.1
CVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu

8.1
CVE-2026-43938

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE

7.8
CVE-2026-41611

Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz

7.7
CVE-2026-2995

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1

7.3
CVE-2026-33080

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and

7.3
CVE-2026-43939

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc

7.2
CVE-2026-46492

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (

7.1
CVE-2025-14835

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet

7.1
CVE-2026-50146

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i

6.9
CVE-2026-54570

AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in An

6.5
CVE-2026-48910

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar

6.4
CVE-2025-15058

The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency'

6.4
CVE-2025-12803

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor

6.4
CVE-2026-1834

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'

6.3
CVE-2026-42451

Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in

6.1
CVE-2025-45286

A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script

6.1
CVE-2026-23528

Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, an

6.1
CVE-2026-24128

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi

6.1
CVE-2026-25578

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site script

6.1
CVE-2026-27116

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulne

6.1
CVE-2025-52563

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne

6.1
CVE-2025-52564

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani

6.1
CVE-2026-20070

A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software an

6.1
CVE-2026-28499

LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct

6.1
CVE-2026-39839

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi

6.1
CVE-2026-39841

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi

6.1
CVE-2026-34718

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic

6.1
CVE-2026-39941

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu

6.1
CVE-2026-26460

A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu

6.1
CVE-2026-40105

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-r

6.1
CVE-2026-20170

A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated,

6.1
CVE-2026-41575

In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was ident

6.1
CVE-2026-42030

MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected X

6.1
CVE-2025-15345

The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par

6.1
CVE-2026-9646

A reflected cross-site scripting issue exists in URL handling.

6.1
CVE-2025-71331

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat

6.1
CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example

6.1
CVE-2026-7380

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno

6.1
CVE-2026-32822

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.

6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme

6.1
CVE-2026-5389

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ

5.9
CVE-2026-29106

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi

5.9
CVE-2026-59838

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.

5.7
CVE-2025-36321

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject

Frequently Asked Questions

What is CWE-80?

CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-80?

There are 139 CVE records associated with CWE-80 in our database. Of these, 2 are critical severity, 13 are high severity, and 95 are medium severity.

How can I protect against CWE-80 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.

Detect CWE-80 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.

Get Started