CWE-80: CWE-80

132
Total CVEs
3
Critical
29
High
6.1
Avg CVSS

Yearly Trend

2026
17
2025
71
2024
36
2023
3
2022
3

Top Affected Vendors

1 Ibm 8
2 Cisco 5
3 Xwiki 4
4 Desktopalert 2
5 Openproject 2
6 Wpbakery 2
7 Redhat 2
8 Apache 2
9 Checkmk 2
10 Getkirby 1

All CWE-80 CVEs (132)

CVE-2025-11161
6.4

The WPBakery Page Builder WordPress plugin has a stored XSS vulnerability in the vc_custom_heading shortcode. Authenticated attackers with contributor...

Oct 15, 2025
CVE-2025-11160
6.4

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious JavaScript code via the WPBakery P...

Oct 15, 2025
CVE-2025-11241
6.4

The Yoast SEO Premium WordPress plugin versions 25.7 to 25.9 contain a stored cross-site scripting vulnerability due to improper input sanitization. A...

Oct 3, 2025
CVE-2025-10128
6.4

This stored XSS vulnerability in the Eulerpool Research Systems WordPress plugin allows authenticated attackers with contributor-level access or highe...

Sep 30, 2025
CVE-2025-10125
6.4

The Memberlite Shortcodes WordPress plugin has a stored XSS vulnerability in its 'row' shortcode that allows authenticated attackers with contributor-...

Sep 17, 2025
CVE-2025-8621
6.4

The Mosaic Generator WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with Contributor-level access or higher to in...

Aug 12, 2025
CVE-2025-4367
6.4

The Download Manager WordPress plugin has a stored XSS vulnerability in all versions up to 3.3.18. Authenticated attackers with author-level access or...

Jun 19, 2025
CVE-2025-4168
6.4

The Subpage List WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to inject...

May 3, 2025
CVE-2025-3521
6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into team member social li...

May 1, 2025
CVE-2024-10621
6.4

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious JavaScript into pages using the Si...

Nov 8, 2024
CVE-2024-7629
6.4

The Responsive Video WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to in...

Aug 21, 2024
CVE-2025-47600
6.1

This Cross-Site Scripting (XSS) vulnerability in the WoodMart WordPress theme allows attackers to inject malicious scripts into web pages. It affects ...

Jan 22, 2026
CVE-2025-45286
6.1

This CVE describes a cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 that allows attackers to inject and execute malicious web s...

Jan 2, 2026
CVE-2025-64225
6.1

This vulnerability allows attackers to inject malicious scripts into web pages through the Stockie Extra WordPress plugin. When exploited, it enables ...

Dec 18, 2025
CVE-2025-54057
6.1

This CVE describes a cross-site scripting (XSS) vulnerability in Apache SkyWalking where malicious script tags can be injected into web pages. It affe...

Nov 27, 2025
CVE-2025-49398
6.1

This vulnerability allows attackers to inject malicious scripts into web pages through the Easy Appointments WordPress plugin. It affects all WordPres...

Nov 6, 2025
CVE-2025-30210
6.1

Bruno API IDE versions before 1.39.1 contain a cross-site scripting vulnerability where environment names are injected as raw HTML. This allows execut...

Apr 1, 2025
CVE-2024-57004
6.1

This Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail allows authenticated users to upload malicious files as email attachments. When rec...

Feb 3, 2025
CVE-2024-12127
6.1

The Sikshya LMS WordPress plugin has a reflected cross-site scripting vulnerability in the 'page' parameter that allows unauthenticated attackers to i...

Dec 17, 2024
CVE-2022-20654
6.1

This cross-site scripting (XSS) vulnerability in Cisco Webex Meetings allows an unauthenticated attacker to execute malicious JavaScript in users' bro...

Nov 15, 2024
CVE-2024-9438
6.1

The SEUR Oficial WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in all versions up to 2.2.11. Unauthenticated attacker...

Oct 29, 2024
CVE-2024-20341
6.1

This vulnerability allows unauthenticated remote attackers to execute cross-site scripting (XSS) attacks against users accessing Cisco ASA/FTD VPN web...

Oct 23, 2024
CVE-2024-8872
6.1

The Store Hours for WooCommerce WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability that allows unauthenticated attackers t...

Sep 26, 2024
CVE-2024-2010
6.1

This vulnerability allows attackers to inject malicious scripts into web pages through improper input sanitization in TE Informatics V5 software. When...

Sep 12, 2024
CVE-2025-31575
5.9

This vulnerability allows attackers to inject malicious scripts into WordPress websites using the Flag Icons plugin. When executed, these scripts can ...

Mar 31, 2025
CVE-2025-29427
5.9

This vulnerability allows attackers to inject malicious scripts into the profile.php page of Code-projects Online Class and Exam Scheduling System V1....

Mar 17, 2025
CVE-2024-54128
5.7

CVE-2024-54128 is an HTML injection vulnerability in Directus's comment feature due to client-side filtering that can be bypassed. This allows attacke...

Dec 5, 2024
CVE-2024-11404
5.5

This vulnerability in django Filer allows attackers to upload malicious files and execute stored cross-site scripting (XSS) attacks. It affects websit...

Nov 20, 2024
CVE-2026-27458
5.4

This CVE describes a stored cross-site scripting (XSS) vulnerability in LinkAce's Atom feed endpoint for lists. An authenticated user can inject malic...

Feb 21, 2026
CVE-2026-25935
5.4

This is a cross-site scripting (XSS) vulnerability in Vikunja todo application where malicious HTML/JavaScript can be injected into task descriptions....

Feb 11, 2026
CVE-2025-45160
5.4

A HTML injection vulnerability in Cacti's file upload functionality allows attackers to inject arbitrary HTML elements into error popups when uploadin...

Jan 29, 2026
CVE-2025-36397
5.4

IBM Application Gateway versions 23.10 through 25.09 are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in us...

Jan 20, 2026
CVE-2025-69169
5.4

This vulnerability allows attackers to inject malicious scripts into web pages through the Easy Media Download WordPress plugin. It affects all WordPr...

Jan 8, 2026
CVE-2025-36230
5.4

IBM Aspera Faspex 5 versions 5.0.0 through 5.0.14.1 contain an HTML injection vulnerability that allows attackers to inject malicious HTML code. When ...

Dec 26, 2025
CVE-2025-66450
5.4

CVE-2025-66450 is a stored cross-site scripting (XSS) vulnerability in LibreChat where attackers can inject malicious code via the iconURL parameter. ...

Dec 11, 2025
CVE-2025-66512
5.4

This vulnerability allows malicious users to bypass Nextcloud's Content Security Policy (CSP) by tricking users into viewing specially crafted SVG fil...

Dec 5, 2025
CVE-2025-11874
5.4

This stored XSS vulnerability in the Slippy Slider WordPress plugin allows authenticated attackers with contributor-level access or higher to inject m...

Nov 11, 2025
CVE-2025-33110
5.4

IBM OpenPages versions 9.0 and 9.1 with Watson are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in victims'...

Nov 6, 2025
CVE-2025-36121
5.4

IBM OpenPages 9.1 and 9.0 contains an HTML injection vulnerability that allows authenticated attackers to inject malicious HTML code. When victims vie...

Oct 27, 2025
CVE-2025-20331
5.4

This stored XSS vulnerability in Cisco ISE and ISE-PIC web management interfaces allows authenticated attackers to inject malicious scripts that execu...

Aug 6, 2025
CVE-2024-49343
5.4

IBM Informix Dynamic Server versions 12.10 and 14.10 contain an HTML injection vulnerability that allows remote attackers to inject malicious HTML cod...

Jul 28, 2025
CVE-2024-51475
5.4

IBM Content Navigator versions 3.0.11, 3.0.15, and 3.1.0 are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes i...

May 16, 2025
CVE-2025-0272
5.4

HCL DevOps Deploy/Launch is vulnerable to HTML injection, allowing authenticated users to embed arbitrary HTML in the web interface. This could lead t...

Apr 3, 2025
CVE-2025-23919
5.4

This Cross-Site Scripting (XSS) vulnerability in the Ella van Durpe Slides & Presentations WordPress plugin allows attackers to inject malicious scrip...

Jan 16, 2025
CVE-2024-41752
5.4

IBM Cognos Analytics is vulnerable to HTML injection where attackers can inject malicious HTML that executes in victims' browsers. This affects IBM Co...

Dec 18, 2024
CVE-2020-26067
5.4

This vulnerability allows an authenticated attacker to inject malicious scripts into Cisco Webex Teams via crafted usernames, potentially stealing sen...

Nov 18, 2024
CVE-2024-20504
5.4

This stored XSS vulnerability in Cisco AsyncOS web management interfaces allows authenticated attackers to inject malicious scripts that execute when ...

Nov 6, 2024
CVE-2023-47513
5.4

This vulnerability allows attackers to inject malicious scripts into web pages created by the ARI Stream Quiz WordPress plugin. When exploited, it ena...

Jun 4, 2024
CVE-2023-45635
5.4

This vulnerability allows attackers to inject malicious scripts into web pages using the WP Darko Responsive Tabs WordPress plugin. When exploited, it...

Jun 4, 2024
CVE-2022-1274
5.4

CVE-2022-1274 is an HTML injection vulnerability in Keycloak's execute-actions-email endpoint that allows attackers to inject arbitrary HTML into emai...

Mar 29, 2023

About CWE-80 (CWE-80)

Our database tracks 132 CVEs classified as CWE-80, with 3 rated critical and 29 rated high severity. The average CVSS score for CWE-80 vulnerabilities is 6.1.

External reference: View CWE-80 on MITRE CWE →

Monitor CWE-80 Vulnerabilities

Get alerted when new CWE-80 CVEs affect your infrastructure.

Start Monitoring Free