CWE-80: CWE-80

132
Total CVEs
3
Critical
29
High
6.1
Avg CVSS

Yearly Trend

2026
17
2025
71
2024
36
2023
3
2022
3

Top Affected Vendors

1 Ibm 8
2 Cisco 5
3 Xwiki 4
4 Desktopalert 2
5 Openproject 2
6 Wpbakery 2
7 Redhat 2
8 Apache 2
9 Checkmk 2
10 Getkirby 1

All CWE-80 CVEs (132)

CVE-2023-39216
9.6

An improper input validation vulnerability in Zoom Desktop Client for Windows allows unauthenticated attackers to escalate privileges via network acce...

Aug 8, 2023
CVE-2024-52300
9.0

CVE-2024-52300 is a cross-site scripting (XSS) vulnerability in the macro-pdfviewer component for XWiki that allows attackers to inject malicious scri...

Nov 13, 2024
CVE-2024-41947
9.0

This XWiki vulnerability allows attackers to inject and execute JavaScript code in the context of higher-privileged users by creating edit conflicts. ...

Jul 31, 2024
CVE-2025-39663
8.4

A Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote monitoring site to inject malicious HTML/Ja...

Oct 30, 2025
CVE-2023-32193
8.3

An unauthenticated cross-site scripting (XSS) vulnerability exists in Norman's public API endpoint, allowing attackers to inject and execute malicious...

Oct 16, 2024
CVE-2024-23841
8.2

CVE-2024-23841 is a cross-site scripting vulnerability in the @apollo/experimental-apollo-client-nextjs NPM package that allows attackers to execute a...

Jan 30, 2024
CVE-2021-29503
8.1

This CVE describes a stored cross-site scripting (XSS) vulnerability in HedgeDoc's YAML metadata processing. Attackers with write access to notes can ...

May 19, 2021
CVE-2025-54346
7.6

A reflected cross-site scripting (XSS) vulnerability in Desktop Alert PingAlert versions 6.1.0.11 through 6.1.1.2 allows attackers to inject malicious...

Nov 14, 2025
CVE-2021-27915
7.6

CVE-2021-27915 is a cross-site scripting (XSS) vulnerability in Mautic's description fields that allows authenticated users with appropriate permissio...

Sep 17, 2024
CVE-2024-35224
7.6

This vulnerability allows stored cross-site scripting (XSS) in OpenProject's Cost Report feature via misconfigured tablesorter dependency. Attackers w...

May 23, 2024
CVE-2022-0989
7.5

The NS WooCommerce Watermark WordPress plugin through version 2.11.3 contains a vulnerability that allows unprivileged users to load images from malic...

Apr 11, 2022
CVE-2024-32484
7.4

A reflected cross-site scripting (XSS) vulnerability in Anki's Flask server allows attackers to execute arbitrary JavaScript by tricking users into op...

Jul 22, 2024
CVE-2024-34507
7.4

This vulnerability allows cross-site scripting (XSS) attacks in MediaWiki due to improper handling of the escape character (0x1b) in comment parsing. ...

May 5, 2024
CVE-2024-33423
7.4

This Cross-Site Scripting (XSS) vulnerability in CMSimple v5.15 allows attackers to inject malicious scripts into the Settings menu's Logout parameter...

May 1, 2024
CVE-2024-33831
7.4

This stored XSS vulnerability in YAPI's Advanced Expectation-Response module allows attackers to inject malicious scripts that execute when users view...

Apr 30, 2024
CVE-2022-29258
7.4

This CVE describes a cross-site scripting (XSS) vulnerability in XWiki Platform Filter UI that allows attackers to inject malicious scripts into form ...

May 31, 2022
CVE-2022-29251
7.4

This CVE describes a cross-site scripting (XSS) vulnerability in XWiki Platform's Flamingo Theme UI. Attackers can inject malicious scripts via the 'n...

May 25, 2022
CVE-2023-3971
7.3

This CVE describes an HTML injection vulnerability in a Controller's user interface settings. Attackers can inject malicious HTML to create fake login...

Oct 4, 2023
CVE-2025-10496
7.2

The Cookie Notice & Consent WordPress plugin up to version 1.6.5 has a stored XSS vulnerability in the uuid parameter. Unauthenticated attackers can i...

Oct 9, 2025
CVE-2024-13497
7.2

The Tripetto WordPress plugin (versions up to 8.0.9) has a stored XSS vulnerability in attachment uploads due to insufficient input sanitization. Unau...

Mar 15, 2025
CVE-2024-13704
7.2

The Super Testimonials WordPress plugin has a stored XSS vulnerability in the 'st_user_title' parameter that allows unauthenticated attackers to injec...

Feb 18, 2025
CVE-2024-4439
7.2

WordPress Core has a stored XSS vulnerability in the Avatar block that allows attackers to inject malicious scripts via user display names. Authentica...

May 3, 2024
CVE-2025-14835
7.1

The WP Photo Album Plus WordPress plugin contains a reflected cross-site scripting vulnerability in the 'shortcode' parameter that allows unauthentica...

Jan 7, 2026
CVE-2025-64764
7.1

A reflected cross-site scripting (XSS) vulnerability exists in Astro web framework when using server islands feature. Attackers can inject malicious s...

Nov 19, 2025
CVE-2025-60244
7.1

This Cross-Site Scripting (XSS) vulnerability in the WordPress TableOn plugin allows attackers to inject malicious scripts into web pages. It affects ...

Nov 6, 2025
CVE-2025-31384
7.1

This vulnerability allows attackers to inject malicious scripts into web pages through the Aviplugins Videos WordPress plugin. When exploited, it enab...

Apr 4, 2025
CVE-2025-22501
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Improve My City WordPress plugin that allows attackers to inject malicious scripts...

Mar 28, 2025
CVE-2024-46910
7.1

An authenticated user in Apache Atlas can inject malicious scripts (XSS) that execute in other users' browsers, potentially allowing impersonation of ...

Feb 13, 2025
CVE-2024-44061
7.1

This vulnerability allows attackers to inject malicious scripts into web pages served by the EU/UK VAT Manager for WooCommerce WordPress plugin. When ...

Oct 20, 2024
CVE-2024-26282
7.1

This vulnerability in Firefox for iOS allows attackers to execute JavaScript on bookmarked AMP pages by manipulating canonical URLs. It affects Firefo...

Feb 22, 2024
CVE-2021-32735
7.1

This vulnerability allows cross-site scripting (XSS) attacks in Kirby CMS Panel's ListItem component. Authenticated Panel users can escalate privilege...

Jul 2, 2021
CVE-2025-51989
7.0

An HTML injection vulnerability in Evolution Consulting's HRmaster module v235 allows attackers to inject malicious HTML tags into the 'keresztnév' (...

Aug 21, 2025
CVE-2025-8386
6.9

This vulnerability allows authenticated users with 'aaConfigTools' privileges to inject malicious scripts into App Objects' help files during configur...

Nov 15, 2025
CVE-2025-62415
6.9

This vulnerability allows authenticated administrators in Bagisto v2.3.7 to upload malicious HTML files containing JavaScript through the TinyMCE imag...

Oct 16, 2025
CVE-2024-47139
6.8

A stored cross-site scripting (XSS) vulnerability in the BIG-IQ Configuration utility allows authenticated administrators to inject malicious JavaScri...

Oct 16, 2024
CVE-2025-54348
6.5

A stored cross-site scripting (XSS) vulnerability in Desktop Alert PingAlert Application Server versions 6.1.0.11 through 6.1.1.2 allows attackers to ...

Nov 14, 2025
CVE-2025-52897
6.5

GLPI versions 9.1.0 through 10.0.18 contain a vulnerability in the planning feature that allows unauthenticated attackers to craft malicious links for...

Jul 30, 2025
CVE-2025-31604
6.5

This vulnerability allows attackers to inject malicious scripts into Cal.com web pages, which execute when other users view those pages. It affects al...

Mar 31, 2025
CVE-2025-31465
6.5

This stored cross-site scripting (XSS) vulnerability in the Better Section Navigation Widget WordPress plugin allows attackers to inject malicious scr...

Mar 28, 2025
CVE-2025-25363
6.5

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) allows attac...

Mar 13, 2025
CVE-2025-24673
6.5

This stored cross-site scripting (XSS) vulnerability in the Ketchup Shortcodes WordPress plugin allows attackers to inject malicious scripts that exec...

Jan 24, 2025
CVE-2023-49852
6.5

This vulnerability allows attackers to inject malicious scripts into web pages using the Responsive Slick Slider WordPress plugin. When exploited, it ...

Jun 4, 2024
CVE-2025-12803
6.4

The Bold Page Builder WordPress plugin has a stored XSS vulnerability in its 'bt_bb_tabs' shortcode. Authenticated attackers with contributor-level ac...

Feb 7, 2026
CVE-2025-15058
6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pricing tables via th...

Jan 7, 2026
CVE-2025-11265
6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages using the V...

Nov 18, 2025
CVE-2025-11267
6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious JavaScript into website pages via ...

Nov 18, 2025
CVE-2025-12753
6.4

The Chart Expert WordPress plugin has a stored XSS vulnerability in the 'pmzez_chart' shortcode that allows authenticated attackers with contributor-l...

Nov 11, 2025
CVE-2025-11745
6.4

This stored XSS vulnerability in the Ad Inserter WordPress plugin allows authenticated attackers with contributor-level access or higher to inject mal...

Nov 5, 2025
CVE-2025-11987
6.4

The Visual Link Preview WordPress plugin up to version 2.2.7 has a stored XSS vulnerability in its shortcode functionality. Authenticated attackers wi...

Nov 5, 2025
CVE-2025-11823
6.4

This stored XSS vulnerability in the ShopLentor WooCommerce Builder plugin allows authenticated attackers with Contributor access or higher to inject ...

Oct 25, 2025

About CWE-80 (CWE-80)

Our database tracks 132 CVEs classified as CWE-80, with 3 rated critical and 29 rated high severity. The average CVSS score for CWE-80 vulnerabilities is 6.1.

External reference: View CWE-80 on MITRE CWE →

Monitor CWE-80 Vulnerabilities

Get alerted when new CWE-80 CVEs affect your infrastructure.

Start Monitoring Free