VYPR

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

VariantIncompleteLikelihood: High

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-18 · CAPEC-193 · CAPEC-32 · CAPEC-86

CVEs mapped to this weakness (602)

page 13 of 31
  • CVE-2022-28648MedApr 5, 2022
    risk 0.37cvss 5.7epss 0.01

    In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

  • CVE-2020-4047MedJun 12, 2020
    risk 0.37cvss 6.8epss 0.03

    In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is…

  • CVE-2025-30161MedMar 31, 2025
    risk 0.36cvss 5.4epss 0.10

    OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This…

  • CVE-2024-54001MedDec 5, 2024
    risk 0.36cvss 5.5epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user…

  • CVE-2008-10001MedMar 28, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. It is recommended to upgrade the affected component. NOTE: This…

  • CVE-2021-39348MedOct 21, 2021
    risk 0.36cvss 5.5epss 0.05

    The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web…

  • CVE-2026-34497MedJul 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2021-47948MedMay 10, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers can inject malicious HTML including image tags and scripts into the Help Text…

  • CVE-2026-39837MedApr 7, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

  • CVE-2026-1834MedMar 31, 2026
    risk 0.35cvss 6.4epss 0.00

    The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…

  • CVE-2025-59540MedMar 6, 2026
    risk 0.35cvss 5.4epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that allows a staff account to execute arbitrary JavaScript in the browser of higher-privileged admin users. The issue arises because feedback input in the…

  • CVE-2025-14289MedFeb 17, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2025-45160MedJan 29, 2026
    risk 0.35cvss 5.4epss 0.00

    A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject…

  • CVE-2025-36397MedJan 20, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2025-69169MedJan 8, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Download easy-media-download allows Reflection Injection.This issue affects Easy Media Download: from n/a through <= 1.1.11.

  • CVE-2025-36230MedDec 26, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2025-11874MedNov 11, 2025
    risk 0.35cvss 5.4epss 0.00

    The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user…

  • CVE-2025-33110MedNov 6, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2025-11987MedNov 5, 2025
    risk 0.35cvss 6.4epss 0.00

    The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2025-36121MedOct 27, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.