The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
Volume of CVEs assigned to CWE-692 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42214MEDIUM HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web | Jul 17, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-15295MEDIUM The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due | Jul 10, 2026 | 4.4 | 26 | NO | NO |
CVE-2025-20240MEDIUM A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) | Sep 24, 2025 | 6.1 | 23 | NO | NO |
CVE-2024-23569MEDIUM HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | Jul 17, 2026 | 4.3 | 22 | NO | NO |
CVE-2023-26047MEDIUM teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack | Mar 3, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-49590MEDIUM CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however thi | Jun 18, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-52305MEDIUM UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a n | Nov 13, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-30924MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component. | Apr 18, 2024 | 4.6 | 16 | NO | NO |
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-s | Jul 16, 2025 | 1.3 | 11 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.