CWE-80

CWE-80 · 6 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-80, highest CVSS first.

  1. HIGH 7.5CVE-2026-57440public PoC

    The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the ur…

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.1CVE-2026-102279public PoC

    Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hov…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-63216public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option label is outp…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-91130public PoC

    Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpo…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-68919public PoC

    GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detai…

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-52741public PoC

    GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with c…

    AI risk analysis on Exploit-DB.ai →