Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers
ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc
md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i
AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in An
A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar
The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency'
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'
Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in
A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script
Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, an
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site script
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulne
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software an
LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic
ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-r
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated,
In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was ident
MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected X
The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par
A reflected cross-site scripting issue exists in URL handling.
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.
XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 139 CVE records associated with CWE-80 in our database. Of these, 2 are critical severity, 13 are high severity, and 95 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started