CWE-83: Improper Neutralization of Script in Attributes in a Web Page

The product does not neutralize or incorrectly neutralizes "javascript:" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.

27 tracked CVEs are classified under this weakness.

Highest-risk vulnerabilities

Recently published

More specific weaknesses

Browse the full CVE database