Threats Tagged 'cwe-80'
View all threats tagged with 'cwe-80'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-80'
Click on any threat for detailed analysis and mitigation recommendations
0 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0. Join the discussion | CVE Database V5 | 09/22/2026, 19:02:38 UTC Added: 09/22/2026, 19:18:25 UTC |
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. Join the discussion | CVE Database V5 | 09/15/2026, 17:03:34 UTC Added: 09/15/2026, 17:32:31 UTC |
0 plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim the text/x-html-safe output type. This equality shortcut bypasses the safe_html transform even though the transform itself correctly removes event-handler attributes and unsafe URI schemes. Equal types can result from a RichText field configured with the same mimeType and outputMimeType or from REST API input that supplies text/x-html-safe as its content type. The raw stored value is then emitted through tal:content=structure without escaping, allowing a user who can set a RichText field to store JavaScript that executes in a viewer's browser. This issue is fixed in versions 2.0.2, 3.0.2, and 4.0.1. Join the discussion | CVE Database V5 | 09/15/2026, 16:38:38 UTC Added: 09/15/2026, 16:47:16 UTC |
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later. Join the discussion | GCVE Database | 09/08/2026, 08:20:03 UTC Added: 09/02/2026, 15:47:49 UTC |
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later. Join the discussion | CVE Database V5 | 09/02/2026, 10:51:17 UTC Added: 09/02/2026, 11:08:00 UTC |
0 CVE-2026-82838 is a medium severity vulnerability in the pretix venueless product where the default docker image did not properly prevent uploaded SVG files from containing executable JavaScript. This issue relates to improper neutralization of script-related HTML tags (CWE-80). A valid Content Security Policy is now set to mitigate this risk. No specific affected versions or patches are currently detailed. Join the discussion | CVE Database V5 | 08/31/2026, 07:44:09 UTC Added: 08/31/2026, 09:07:52 UTC |
CVE-2026-5218 is a medium severity vulnerability in Softtr Informatics Technology Trading Limited Company's E-Commerce Pack. It involves improper neutralization of script-related HTML tags, leading to a basic Cross-Site Scripting (XSS) issue. This vulnerability affects versions before 5.03.01.49. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/27/2026, 11:12:03 UTC Added: 08/27/2026, 13:07:53 UTC |
0 CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx passes attacker-controlled guide Markdown to MDEditor without the rehype-sanitize plugin. A user who can create or edit an annotation guide can store malicious JavaScript that executes when another user opens the guide. The script can issue arbitrary CVAT requests with the victim user's privileges. This issue is fixed in version 2.70.0. Join the discussion | CVE Database V5 | 08/20/2026, 14:32:52 UTC Added: 08/20/2026, 14:38:09 UTC |
0 Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3. Join the discussion | GCVE Database | 08/20/2026, 00:00:00 UTC Added: 07/02/2026, 22:57:07 UTC |
0 HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email. Join the discussion | CVE Database V5 | 08/18/2026, 14:06:37 UTC Added: 08/18/2026, 14:21:07 UTC |
Showing 1 to 10 of 162 results