Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

559
Assigned CVEs
74th
Commonality Rank
5.8
Avg CVSS
0.5%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-80 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2006
20 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

559 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-13965MEDIUM
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre
Jun 9, 20206.190YESNO
CVE-2018-19953MEDIUM
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4
Oct 28, 20206.172YESNO
CVE-2024-4439MEDIUM
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the di
May 3, 20246.171NOYES
CVE-2018-19943MEDIUM
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS
Oct 28, 20205.466YESNO
CVE-2022-36094CRITICAL
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's p
Sep 8, 20229.064NONO
CVE-2022-36096CRITICAL
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6
Sep 8, 20229.061NONO
CVE-2022-21145MEDIUM
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrar
Apr 14, 20224.858NONO
CVE-2020-13562MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.156NONO
CVE-2020-13564MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.155NONO
CVE-2020-13563MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.155NONO
View all 559 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
11%
10%
4.0-4.9
34%
19%
5.0-5.9
41%
16%
6.0-6.9
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
3 CVEs
0.5% of CVEs· 85th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
1.6% of CVEs· 88th percentile
ExploitDB
4 CVEs
0.7% of CVEs· 78th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products