Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Virames Vira-Investing al
Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Start
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an una
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an una
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect a
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulne
A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the U
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. T
ViewVC is a browser interface for CVS and Subversion version control repositories. Versions prior to 1.2.3 and 1.1.30 ar
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service v
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versio
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allow
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output i
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin
A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects s
A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been classified as problematic
Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient e
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with vers
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki P
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki
sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting wi
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platfo
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stre
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow
Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the si
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started