A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an un
A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the f
A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part.
A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknow
A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown proces
A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown functi
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability
A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unk
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is
A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scriptin
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to co
A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, t
Wrongthink is an encrypted peer-to-peer chat program. A user could check their fingerprint into the service and enter a
A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability a
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0
This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a
The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to
jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via ma
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was di
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in Fi
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has al
touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HT
matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issu
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V
A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-S
A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web applica
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has al
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the
A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started