SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6
A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug
A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file
A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032
A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/departm
IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vuln
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML
A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Sit
It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page.
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to
Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 t
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnera
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a c
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't
ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-control
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API
A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint
apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nex
OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cos
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic
WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconne
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows a
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary we
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3,
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versio
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 1
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. Th
The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saleswonder Team: Tobias
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.1
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of fi
GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on o
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive
Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)
Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scr
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to
The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings f
The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started