CWE-80: Basic XSS
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
548 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-41810 — HTML injection in HTTP redirect body
- CVE-2025-66481 — DeepChat's Incomplete XSS Fix Allows RCE through Mermaid Content
- CVE-2024-34070 — Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise
- CVE-2024-39363 — A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300
- CVE-2025-53883 — spacewalk-java has various XSS issues on search page
- CVE-2026-32891 — Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
- CVE-2025-54117 — NamelessMC allows Stored Cross-Site Scripting (XSS) in dashboard text editor
- CVE-2025-53835 — XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
- CVE-2024-52300 — macro-pdfviewer has a XSS through the width parameter
- CVE-2024-41947 — XWiki Platform XSS through conflict resolution
- CVE-2024-37166 — ghtml Cross-Site Scripting (XSS) vulnerability
- CVE-2025-4278 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
- CVE-2025-30210 — Bruno XSS On Environment Name
- CVE-2024-51735 — Stored Cross-site Scripting to RCE on Osmedeus Web Server
- CVE-2026-25935 — Vikunja Affected by XSS Via Task Preview
- CVE-2025-66450 — LibreChat JSON Injection in Chat POST Allows Remote Resource Inclusion and PXSS via Image Upload
- CVE-2025-58430 — listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover
- CVE-2025-53093 — TabberNeue vulnerable to Stored XSS through wikitext
- CVE-2025-21612 — Cross-site Scripting in TabberTransclude in Extension:TabberNeue
- CVE-2026-32753 — FreeScout: Stored XSS through SVG file upload with filter bypass
Recently published
- CVE-2026-52774 — Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
- CVE-2026-52773 — Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
- CVE-2026-32773 — Apache Spark: XSS Vulnerability in Spark Web 3.5.4
- CVE-2026-82838 — Default webserver configuration with incorrect CSP
- CVE-2026-55696 — PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
- CVE-2026-5218 — HTML Injection in Softtr's E-Commerce Pack
- CVE-2026-5389 — justhtml before 1.13.0 XSS via code fence breakout
- CVE-2026-35163 — OctoPrint: XSS in Suppressed Command Notifications
- CVE-2026-73220 — CVAT: Stored XSS via annotation guides in audio tasks
- CVE-2026-20232 — Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
- CVE-2026-52854 — mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser function
- CVE-2026-54570 — AngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
- CVE-2026-75872 — HTML Injection in MailerUp double opt-in verification email
- CVE-2026-75082 — Webkul Bagisto Customer-Registration Notification Email register cross site scripting
- CVE-2026-19988 — Alaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting
- CVE-2026-73237 — Apache Allura: XSS in markdown pipeline
- CVE-2026-73238 — Apache Allura: XSS in code display
- CVE-2026-65841 — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
- CVE-2026-34497 — FMS Employee Vulnerable to HTML Injection
- CVE-2026-48910 — Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing