A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/
A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNS
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes t
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin da
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quaranti
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user das
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke
The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scri
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST
Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF
Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em
Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTa
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the au
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Comman
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300
DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain cond
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't es
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistor
An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas version
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Improve My City Improve M
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows
Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat
HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an a
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started