131 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-11707 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc | CRITICAL | 9.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-66418 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack | CRITICAL | 9.3 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-66421 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to | HIGH | 8.8 | 29%ile | NVD | 2026-07-30 |
| CVE-2026-13609 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af | HIGH | 8.8 | 16%ile | NVD | 2026-07-31 |
| CVE-2026-67328 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling | HIGH | 8.6 | 20%ile | NVD | 2026-08-01 |
| CVE-2026-69149 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other | HIGH | 8.6 | 27%ile | NVD | 2026-08-03 |
| CVE-2026-56670 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo | HIGH | 8.2 | 13%ile | NVD | 2026-07-31 |
| CVE-2026-56672 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control | HIGH | 8.2 | 15%ile | NVD | 2026-07-31 |
| CVE-2026-48060 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which | HIGH | 8.1 | 21%ile | NVD | 2026-07-28 |
| CVE-2026-16969 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | HIGH | 7.6 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-18360 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | HIGH | 7.6 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-18361 | The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the | HIGH | 7.6 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-69151 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other | HIGH | 7.6 | 25%ile | NVD | 2026-08-03 |
| CVE-2026-13425 | The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al | HIGH | 7.2 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-16597 | The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr | HIGH | 7.2 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-16655 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne | HIGH | 7.2 | 23%ile | NVD | 2026-07-29 |
| CVE-2026-15052 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr | HIGH | 7.2 | 15%ile | NVD | 2026-08-01 |
| CVE-2026-14234 | The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin | HIGH | 7.1 | 1%ile | NVD | 2026-07-29 |
| CVE-2026-69075 | FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c | MEDIUM | 6.9 | 21%ile | NVD | 2026-08-03 |
| CVE-2026-69092 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo | MEDIUM | 6.9 | 13%ile | NVD | 2026-08-03 |
| CVE-2026-18243 | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat | MEDIUM | 6.9 | 8%ile | NVD | 2026-08-03 |
| CVE-2026-13605 | The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca | MEDIUM | 6.8 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-14318 | The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H | MEDIUM | 6.8 | 24%ile | NVD | 2026-07-30 |
| CVE-2026-14833 | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend | MEDIUM | 6.8 | 15%ile | NVD | 2026-07-31 |
| CVE-2026-67352 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows | MEDIUM | 6.8 | 12%ile | NVD | 2026-08-01 |
| CVE-2026-16069 | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t | MEDIUM | 6.8 | 5%ile | NVD | 2026-08-04 |
| CVE-2026-16293 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po | MEDIUM | 6.8 | 5%ile | NVD | 2026-08-04 |
| CVE-2024-30053 | Azure Migrate Cross-Site Scripting Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2026-12938 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the | MEDIUM | 6.4 | 12%ile | NVD | 2026-07-29 |
| CVE-2026-12939 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p | MEDIUM | 6.4 | 12%ile | NVD | 2026-07-29 |
| CVE-2026-15735 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' | MEDIUM | 6.4 | 9%ile | NVD | 2026-07-29 |
| CVE-2026-17161 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc | MEDIUM | 6.4 | 9%ile | NVD | 2026-07-29 |
| CVE-2026-17162 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc | MEDIUM | 6.4 | 9%ile | NVD | 2026-07-29 |
| CVE-2026-18197 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow | MEDIUM | 6.4 | 19%ile | NVD | 2026-07-29 |
| CVE-2026-7436 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text | MEDIUM | 6.4 | 9%ile | NVD | 2026-07-29 |
| CVE-2026-8791 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` | MEDIUM | 6.4 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-13362 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_ | MEDIUM | 6.4 | 10%ile | NVD | 2026-08-01 |
| CVE-2026-7623 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cros | MEDIUM | 6.4 | 11%ile | NVD | 2026-08-01 |
| CVE-2026-13458 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML A | MEDIUM | 6.4 | 23%ile | NVD | 2026-08-01 |
| CVE-2026-15644 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'st | MEDIUM | 6.4 | 11%ile | NVD | 2026-08-01 |
| CVE-2026-15645 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'na | MEDIUM | 6.4 | 11%ile | NVD | 2026-08-01 |
| CVE-2026-15649 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho | MEDIUM | 6.4 | 10%ile | NVD | 2026-08-01 |
| CVE-2026-15662 | The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Sit | MEDIUM | 6.4 | 14%ile | NVD | 2026-08-01 |
| CVE-2026-15950 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress | MEDIUM | 6.4 | 9%ile | NVD | 2026-08-01 |
| CVE-2026-16090 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is | MEDIUM | 6.4 | 9%ile | NVD | 2026-08-01 |
| CVE-2026-16091 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is | MEDIUM | 6.4 | 10%ile | NVD | 2026-08-01 |
| CVE-2026-16684 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact | MEDIUM | 6.4 | 9%ile | NVD | 2026-08-01 |
| CVE-2026-16685 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in | MEDIUM | 6.4 | 15%ile | NVD | 2026-08-01 |
| CVE-2026-18062 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S | MEDIUM | 6.4 | 11%ile | NVD | 2026-08-01 |
| CVE-2026-18435 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S | MEDIUM | 6.4 | 9%ile | NVD | 2026-08-01 |
| CVE-2026-12231 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info | MEDIUM | 6.4 | 17%ile | NVD | 2026-08-02 |
| CVE-2026-18481 | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate | MEDIUM | 6.2 | 20%ile | NVD | 2026-07-31 |
| CVE-2026-14515 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptin | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-28 |
| CVE-2026-65946 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-29 |
| CVE-2026-66490 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-29 |
| CVE-2025-65337 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-29 |
| CVE-2026-17797 | Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17818 | Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbi | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17827 | Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17845 | Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17853 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compr | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17878 | Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17962 | Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitr | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-11881 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration setting | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-13330 | The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it ad | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-14207 | The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field befor | MEDIUM | 6.1 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-14592 | The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks befor | MEDIUM | 6.1 | 11%ile | NVD | 2026-07-30 |
| CVE-2025-0152 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1 | MEDIUM | 6.1 | 6%ile | NVD | 2026-07-30 |
| CVE-2025-51684 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data | MEDIUM | 6.1 | 12%ile | NVD | 2026-07-30 |
| CVE-2025-65341 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-30 |
| CVE-2025-65342 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-30 |
| CVE-2026-61526 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through | MEDIUM | 6.1 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-14845 | The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re | MEDIUM | 6.1 | 6%ile | NVD | 2026-07-31 |
| CVE-2026-14921 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_ | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-31 |
| CVE-2026-14922 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-31 |
| CVE-2026-52232 | A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build | MEDIUM | 6.1 | 5%ile | NVD | 2026-07-31 |
| CVE-2026-17571 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne | MEDIUM | 6.1 | 11%ile | NVD | 2026-08-01 |
| CVE-2026-18344 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par | MEDIUM | 6.1 | 12%ile | NVD | 2026-08-01 |
| CVE-2026-14841 | The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle | MEDIUM | 6.1 | 8%ile | NVD | 2026-08-02 |
| CVE-2026-13340 | The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz ext | MEDIUM | 6.1 | 8%ile | NVD | 2026-08-03 |
| CVE-2026-15383 | The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whic | MEDIUM | 6.1 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-15931 | The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthent | MEDIUM | 6.1 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-38444 | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is | MEDIUM | 6.1 | 23%ile | NVD | 2026-08-03 |
| CVE-2026-38446 | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e | MEDIUM | 6.1 | 16%ile | NVD | 2026-08-03 |
| CVE-2026-10032 | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U | MEDIUM | 6.1 | — | NVD | 2026-08-04 |
| CVE-2026-17728 | Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject a | MEDIUM | 5.4 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17734 | Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arb | MEDIUM | 5.4 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17903 | Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local n | MEDIUM | 5.4 | 2%ile | NVD | 2026-07-30 |
| CVE-2025-36298 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 | MEDIUM | 5.4 | 6%ile | NVD | 2026-07-30 |
| CVE-2025-36431 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera | MEDIUM | 5.4 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-11383 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri | MEDIUM | 5.4 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-62324 | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem | MEDIUM | 5.4 | 8%ile | NVD | 2026-07-31 |
| CVE-2026-12696 | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-01 |
| CVE-2026-14292 | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t | MEDIUM | 5.4 | 6%ile | NVD | 2026-08-01 |
| CVE-2026-15234 | The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-01 |
| CVE-2026-15262 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-01 |
| CVE-2026-14864 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-02 |
| CVE-2026-15385 | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-02 |
| CVE-2026-16063 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont | MEDIUM | 5.4 | 3%ile | NVD | 2026-08-02 |
| CVE-2026-14192 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and | MEDIUM | 5.4 | 7%ile | NVD | 2026-08-04 |
| CVE-2026-59232 | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding | MEDIUM | 5.3 | 23%ile | NVD | 2026-07-31 |
| CVE-2026-46594 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio | MEDIUM | 5.1 | 28%ile | NVD | 2026-07-31 |
| CVE-2025-71404 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the | MEDIUM | 5.1 | 33%ile | NVD | 2026-08-01 |
| CVE-2026-67333 | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi | MEDIUM | 5.1 | 5%ile | NVD | 2026-08-01 |
| CVE-2026-67338 | JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to vali | MEDIUM | 5.1 | 7%ile | NVD | 2026-08-01 |
| CVE-2026-68583 | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th | MEDIUM | 5.1 | 4%ile | NVD | 2026-08-02 |
| CVE-2026-66296 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit | MEDIUM | 5.1 | 23%ile | NVD | 2026-08-03 |
| CVE-2026-49131 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir | MEDIUM | 5.1 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-49132 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec | MEDIUM | 5.1 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-67196 | Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in | MEDIUM | 5.1 | — | NVD | 2026-08-04 |
| CVE-2026-15920 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field( | MEDIUM | 5.1 | — | NVD | 2026-08-04 |
| CVE-2026-13344 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta | MEDIUM | 4.8 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-34495 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F | MEDIUM | 4.8 | 34%ile | NVD | 2026-07-31 |
| CVE-2026-34497 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste | MEDIUM | 4.8 | 34%ile | NVD | 2026-07-31 |
| CVE-2025-15669 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren | MEDIUM | 4.8 | 7%ile | NVD | 2026-08-01 |
| CVE-2025-15675 | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor | MEDIUM | 4.8 | 7%ile | NVD | 2026-08-02 |
| CVE-2026-67612 | OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al | MEDIUM | 4.8 | 4%ile | NVD | 2026-08-03 |
| CVE-2026-67617 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al | MEDIUM | 4.8 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-3093 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1 | MEDIUM | 4.7 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-16273 | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field | MEDIUM | 4.6 | 3%ile | NVD | 2026-08-02 |
| CVE-2026-14337 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use | MEDIUM | 4.6 | — | NVD | 2026-08-04 |
| CVE-2026-17739 | Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced | MEDIUM | 4.2 | 4%ile | NVD | 2026-07-30 |
| CVE-2026-59328 | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse | MEDIUM | 4.2 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-13393 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item | LOW | 3.5 | 4%ile | NVD | 2026-07-31 |
| CVE-2026-18682 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api | LOW | 1.3 | 16%ile | NVD | 2026-08-03 |
| CVE-2026-14239 | The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro | UNKNOWN | — | 3%ile | NVD | 2026-07-30 |
| CVE-2026-13725 | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user | UNKNOWN | — | 7%ile | NVD | 2026-08-01 |
| CVE-2026-52520 | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/ | UNKNOWN | — | 10%ile | NVD | 2026-08-03 |
| FG-IR-26-149 | Cross-Site Scripting in Domain parameter | UNKNOWN | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-150 | SSL-VPN Reflected XSS | UNKNOWN | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-110 | Multiple Stored XSS | UNKNOWN | — | — | Fortinet | 2026-04-14 |