Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-80'

View all threats tagged with 'cwe-80'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-80

Threats Tagged 'cwe-80'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-65841: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in xdan joditCVE-2026-65841
0

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.

Join the discussion
CVE-2026-34497: CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) in Johnson Controls FM Systems EmployeeCVE-2026-34497
0

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

Join the discussion
CVE-2026-48910: CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Apache Software Foundation Apache JSPWikiCVE-2026-48910
0

Apache JSPWiki versions up to 2.12.3 contain a cross-site scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags when parsing markdown rendering errors. This flaw allows an attacker to execute JavaScript in the victim's browser, potentially exposing sensitive information. The issue is fixed in version 2.12.4.

Join the discussion
CVE-2026-32822: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in datacycle-engine dataCycle-CORECVE-2026-32822
0

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any unauthenticated attacker can place arbitrary HTML into flash notifications on public routes and rely on the frontend toast component to inject that content into the DOM with `innerHTML`. This creates a reflected DOM XSS that can be delivered with a crafted link to a public page such as `/docs`. Because the vulnerable JavaScript is loaded by the normal application layout, the issue is not limited to a special debug page or an isolated admin-only view.

Join the discussion
CVE-2026-54443: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in lissy93 dashyCVE-2026-54443
0

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-80
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses