← Back
CWE-80

562 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

JSON object

Loading...

CVEs (562)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmsimple
1Cmsimple
Jun 17, 2026
May 1, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language sectio...Show more
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section.Show less
-
-
Jun 17, 2026
May 1, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has uploa...Show more
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a malicious file name like `<img src=x onerror=alert(1)>.txt` will allow JavaScript code execution in the context of the web server’s domain. SWS generally does not perform escaping of HTML entities on any values inserted in the directory listing. At the very least `file_name` and `current_path` could contain malicious data however. `file_uri` could also be malicious but the relevant scenarios seem to be all caught by hyper. For any web server that allow users to upload files or create directories under a name of their choosing this becomes a stored Cross-site Scripting vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
-
-
Jun 17, 2026
Apr 30, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field...Show more
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field.Show less
-
-
Jun 17, 2026
Apr 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.
1Metagauss
1Registrationmagic
Jun 17, 2026
Apr 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
-
-
Jun 17, 2026
Apr 23, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who...Show more
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks enabled and do not trust their Markdown content files. The issue is patched in v0.125.3. As a workaround, replace the templates with user defined templates or disable the internal templates.Show less
2Aiohttp
Fedoraproject
2Aiohttp
Fedora
Jun 17, 2026
Apr 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a...Show more
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.Show less
-
-
Jun 17, 2026
Apr 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the edi...Show more
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without properly sanitizing against HTML injection. Second by improperly sanitizing against attribute HTML injection. This in conjunction with allowing `allow-same-origin` sandbox flag (necessary for several embeds) resulted in the XSS. This vulnerability is fixed in 0.17.6 and 0.16.4.Show less
1Wondercms
1Wondercms
Jun 17, 2026
Apr 17, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu modul...Show more
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.Show less
1Combodo
1Itop
Jun 17, 2026
Apr 15, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.
1Combodo
1Itop
Jun 17, 2026
Apr 15, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.
1Tcpdf Project
1Tcpdf
Jun 17, 2026
Apr 15, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
1Checkmk
1Checkmk
Jun 17, 2026
Apr 5, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in graph rendering in Checkmk <2.3.0b4.
1Esri
1Portal For Arcgis
Jun 17, 2026
Apr 4, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the...Show more
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.Show less
1Cisco
6Rv016 Firmware
Rv042 FirmwareRv042g Firmware+3 more
Jun 17, 2026
Apr 3, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)...Show more
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less
1Munyweki
1Insurance Management System
Jun 17, 2026
Mar 28, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Mar 25, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTM...Show more
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might affect other users. _Also, requires that adding new FAQs is allowed for guests and that the admin doesn't check the content of a newly added FAQ._ This vulnerability is fixed in 3.2.6.Show less
1Bmc
1Control M
Jun 17, 2026
Mar 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for exa...Show more
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200. Show less
1Webedition
1Webedition Cms
Jun 17, 2026
Mar 14, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
1Mozilla
1Firefox
Jun 17, 2026
Feb 22, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.