The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.
Volume of CVEs assigned to CWE-84 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58444HIGH The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior | Sep 8, 2025 | 8.6 | 30 | NO | NO |
CVE-2026-54443MEDIUM Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before render | Jul 15, 2026 | 5.9 | 28 | NO | NO |
CVE-2022-40181HIGH A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126 | Oct 11, 2022 | 8.3 | 27 | NO | NO |
CVE-2024-52890MEDIUM IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs. | Aug 5, 2025 | 6.1 | 21 | NO | NO |
CVE-2021-3824MEDIUM OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL. | Sep 23, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-7011MEDIUM Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a resul | Jun 3, 2020 | 6.1 | 21 | NO | NO |
CVE-2025-25329MEDIUM An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link. | Feb 27, 2025 | 5.5 | 18 | NO | NO |
CVE-2025-25334MEDIUM An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link. | Feb 27, 2025 | 5.5 | 18 | NO | NO |
CVE-2025-25331MEDIUM An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link. | Feb 27, 2025 | 5.5 | 18 | NO | NO |
CVE-2025-25325MEDIUM An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link. | Feb 27, 2025 | 5.5 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.