CWE-80: CWE-80
Yearly Trend
Top Affected Vendors
All CWE-80 CVEs (132)
The WPBakery Page Builder WordPress plugin has a stored XSS vulnerability in the vc_custom_heading shortcode. Authenticated attackers with contributor...
Oct 15, 2025This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious JavaScript code via the WPBakery P...
Oct 15, 2025The Yoast SEO Premium WordPress plugin versions 25.7 to 25.9 contain a stored cross-site scripting vulnerability due to improper input sanitization. A...
Oct 3, 2025This stored XSS vulnerability in the Eulerpool Research Systems WordPress plugin allows authenticated attackers with contributor-level access or highe...
Sep 30, 2025The Memberlite Shortcodes WordPress plugin has a stored XSS vulnerability in its 'row' shortcode that allows authenticated attackers with contributor-...
Sep 17, 2025The Mosaic Generator WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with Contributor-level access or higher to in...
Aug 12, 2025The Download Manager WordPress plugin has a stored XSS vulnerability in all versions up to 3.3.18. Authenticated attackers with author-level access or...
Jun 19, 2025The Subpage List WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to inject...
May 3, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into team member social li...
May 1, 2025This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious JavaScript into pages using the Si...
Nov 8, 2024The Responsive Video WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to in...
Aug 21, 2024This Cross-Site Scripting (XSS) vulnerability in the WoodMart WordPress theme allows attackers to inject malicious scripts into web pages. It affects ...
Jan 22, 2026This CVE describes a cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 that allows attackers to inject and execute malicious web s...
Jan 2, 2026This vulnerability allows attackers to inject malicious scripts into web pages through the Stockie Extra WordPress plugin. When exploited, it enables ...
Dec 18, 2025This CVE describes a cross-site scripting (XSS) vulnerability in Apache SkyWalking where malicious script tags can be injected into web pages. It affe...
Nov 27, 2025This vulnerability allows attackers to inject malicious scripts into web pages through the Easy Appointments WordPress plugin. It affects all WordPres...
Nov 6, 2025Bruno API IDE versions before 1.39.1 contain a cross-site scripting vulnerability where environment names are injected as raw HTML. This allows execut...
Apr 1, 2025This Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail allows authenticated users to upload malicious files as email attachments. When rec...
Feb 3, 2025The Sikshya LMS WordPress plugin has a reflected cross-site scripting vulnerability in the 'page' parameter that allows unauthenticated attackers to i...
Dec 17, 2024This cross-site scripting (XSS) vulnerability in Cisco Webex Meetings allows an unauthenticated attacker to execute malicious JavaScript in users' bro...
Nov 15, 2024The SEUR Oficial WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in all versions up to 2.2.11. Unauthenticated attacker...
Oct 29, 2024This vulnerability allows unauthenticated remote attackers to execute cross-site scripting (XSS) attacks against users accessing Cisco ASA/FTD VPN web...
Oct 23, 2024The Store Hours for WooCommerce WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability that allows unauthenticated attackers t...
Sep 26, 2024This vulnerability allows attackers to inject malicious scripts into web pages through improper input sanitization in TE Informatics V5 software. When...
Sep 12, 2024This vulnerability allows attackers to inject malicious scripts into WordPress websites using the Flag Icons plugin. When executed, these scripts can ...
Mar 31, 2025This vulnerability allows attackers to inject malicious scripts into the profile.php page of Code-projects Online Class and Exam Scheduling System V1....
Mar 17, 2025CVE-2024-54128 is an HTML injection vulnerability in Directus's comment feature due to client-side filtering that can be bypassed. This allows attacke...
Dec 5, 2024This vulnerability in django Filer allows attackers to upload malicious files and execute stored cross-site scripting (XSS) attacks. It affects websit...
Nov 20, 2024This CVE describes a stored cross-site scripting (XSS) vulnerability in LinkAce's Atom feed endpoint for lists. An authenticated user can inject malic...
Feb 21, 2026This is a cross-site scripting (XSS) vulnerability in Vikunja todo application where malicious HTML/JavaScript can be injected into task descriptions....
Feb 11, 2026A HTML injection vulnerability in Cacti's file upload functionality allows attackers to inject arbitrary HTML elements into error popups when uploadin...
Jan 29, 2026IBM Application Gateway versions 23.10 through 25.09 are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in us...
Jan 20, 2026This vulnerability allows attackers to inject malicious scripts into web pages through the Easy Media Download WordPress plugin. It affects all WordPr...
Jan 8, 2026IBM Aspera Faspex 5 versions 5.0.0 through 5.0.14.1 contain an HTML injection vulnerability that allows attackers to inject malicious HTML code. When ...
Dec 26, 2025CVE-2025-66450 is a stored cross-site scripting (XSS) vulnerability in LibreChat where attackers can inject malicious code via the iconURL parameter. ...
Dec 11, 2025This vulnerability allows malicious users to bypass Nextcloud's Content Security Policy (CSP) by tricking users into viewing specially crafted SVG fil...
Dec 5, 2025This stored XSS vulnerability in the Slippy Slider WordPress plugin allows authenticated attackers with contributor-level access or higher to inject m...
Nov 11, 2025IBM OpenPages versions 9.0 and 9.1 with Watson are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes in victims'...
Nov 6, 2025IBM OpenPages 9.1 and 9.0 contains an HTML injection vulnerability that allows authenticated attackers to inject malicious HTML code. When victims vie...
Oct 27, 2025This stored XSS vulnerability in Cisco ISE and ISE-PIC web management interfaces allows authenticated attackers to inject malicious scripts that execu...
Aug 6, 2025IBM Informix Dynamic Server versions 12.10 and 14.10 contain an HTML injection vulnerability that allows remote attackers to inject malicious HTML cod...
Jul 28, 2025IBM Content Navigator versions 3.0.11, 3.0.15, and 3.1.0 are vulnerable to HTML injection, allowing attackers to inject malicious HTML that executes i...
May 16, 2025HCL DevOps Deploy/Launch is vulnerable to HTML injection, allowing authenticated users to embed arbitrary HTML in the web interface. This could lead t...
Apr 3, 2025This Cross-Site Scripting (XSS) vulnerability in the Ella van Durpe Slides & Presentations WordPress plugin allows attackers to inject malicious scrip...
Jan 16, 2025IBM Cognos Analytics is vulnerable to HTML injection where attackers can inject malicious HTML that executes in victims' browsers. This affects IBM Co...
Dec 18, 2024This vulnerability allows an authenticated attacker to inject malicious scripts into Cisco Webex Teams via crafted usernames, potentially stealing sen...
Nov 18, 2024This stored XSS vulnerability in Cisco AsyncOS web management interfaces allows authenticated attackers to inject malicious scripts that execute when ...
Nov 6, 2024This vulnerability allows attackers to inject malicious scripts into web pages created by the ARI Stream Quiz WordPress plugin. When exploited, it ena...
Jun 4, 2024This vulnerability allows attackers to inject malicious scripts into web pages using the WP Darko Responsive Tabs WordPress plugin. When exploited, it...
Jun 4, 2024CVE-2022-1274 is an HTML injection vulnerability in Keycloak's execute-actions-email endpoint that allows attackers to inject arbitrary HTML into emai...
Mar 29, 2023About CWE-80 (CWE-80)
Our database tracks 132 CVEs classified as CWE-80, with 3 rated critical and 29 rated high severity. The average CVSS score for CWE-80 vulnerabilities is 6.1.
External reference: View CWE-80 on MITRE CWE →
Monitor CWE-80 Vulnerabilities
Get alerted when new CWE-80 CVEs affect your infrastructure.
Start Monitoring Free