Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par
IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embedda
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index page
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown f
Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment includ
The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a craft
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo`
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows
The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a
Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential c
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir
The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik
The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker
2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior
The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu
ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st
IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var
Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fie
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fie
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basi
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the
facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application vers
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrate
Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote m
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discu
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accord
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz
WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allo
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute
Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo rig
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started