The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
Volume of CVEs assigned to CWE-80 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
559 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13965MEDIUM An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre | Jun 9, 2020 | 6.1 | 90 | YES | NO |
CVE-2018-19953MEDIUM If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4 | Oct 28, 2020 | 6.1 | 72 | YES | NO |
CVE-2024-4439MEDIUM WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the di | May 3, 2024 | 6.1 | 71 | NO | YES |
CVE-2018-19943MEDIUM If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS | Oct 28, 2020 | 5.4 | 66 | YES | NO |
CVE-2022-36094CRITICAL XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's p | Sep 8, 2022 | 9.0 | 64 | NO | NO |
CVE-2022-36096CRITICAL The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 | Sep 8, 2022 | 9.0 | 61 | NO | NO |
CVE-2022-21145MEDIUM A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrar | Apr 14, 2022 | 4.8 | 58 | NO | NO |
CVE-2020-13562MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 56 | NO | NO |
CVE-2020-13564MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 55 | NO | NO |
CVE-2020-13563MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 55 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.