← Back to feed Search feed

CWE-79 Cross-Site Scripting (XSS) vulnerabilities

131 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-11707IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scCRITICAL9.312%ileNVD2026-07-30
CVE-2026-66418OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackCRITICAL9.326%ileNVD2026-07-30
CVE-2026-66421OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to HIGH8.829%ileNVD2026-07-30
CVE-2026-13609The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value afHIGH8.816%ileNVD2026-07-31
CVE-2026-67328@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling HIGH8.620%ileNVD2026-08-01
CVE-2026-69149Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and otherHIGH8.627%ileNVD2026-08-03
CVE-2026-56670ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoHIGH8.213%ileNVD2026-07-31
CVE-2026-56672ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlHIGH8.215%ileNVD2026-07-31
CVE-2026-48060Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances whichHIGH8.121%ileNVD2026-07-28
CVE-2026-16969The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.68%ileNVD2026-07-30
CVE-2026-18360The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.619%ileNVD2026-07-30
CVE-2026-18361The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.619%ileNVD2026-07-30
CVE-2026-69151Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and otherHIGH7.625%ileNVD2026-08-03
CVE-2026-13425The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in alHIGH7.216%ileNVD2026-07-29
CVE-2026-16597The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site ScrHIGH7.215%ileNVD2026-07-29
CVE-2026-16655The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulneHIGH7.223%ileNVD2026-07-29
CVE-2026-15052The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored CrHIGH7.215%ileNVD2026-08-01
CVE-2026-14234The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowinHIGH7.11%ileNVD2026-07-29
CVE-2026-69075FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-cMEDIUM6.921%ileNVD2026-08-03
CVE-2026-69092Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoMEDIUM6.913%ileNVD2026-08-03
CVE-2026-18243Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticatMEDIUM6.98%ileNVD2026-08-03
CVE-2026-13605The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caMEDIUM6.815%ileNVD2026-07-29
CVE-2026-14318The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HMEDIUM6.824%ileNVD2026-07-30
CVE-2026-14833The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendMEDIUM6.815%ileNVD2026-07-31
CVE-2026-67352luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows MEDIUM6.812%ileNVD2026-08-01
CVE-2026-16069The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted tMEDIUM6.85%ileNVD2026-08-04
CVE-2026-16293The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its PoMEDIUM6.85%ileNVD2026-08-04
CVE-2024-30053Azure Migrate Cross-Site Scripting VulnerabilityMEDIUM6.558%ileMicrosoft2024-05-14
CVE-2026-12938The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of theMEDIUM6.412%ileNVD2026-07-29
CVE-2026-12939The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the pMEDIUM6.412%ileNVD2026-07-29
CVE-2026-15735The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'MEDIUM6.49%ileNVD2026-07-29
CVE-2026-17161The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM6.49%ileNVD2026-07-29
CVE-2026-17162The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM6.49%ileNVD2026-07-29
CVE-2026-18197Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allowMEDIUM6.419%ileNVD2026-07-29
CVE-2026-7436The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'textMEDIUM6.49%ileNVD2026-07-29
CVE-2026-8791The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` MEDIUM6.415%ileNVD2026-07-29
CVE-2026-13362The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_MEDIUM6.410%ileNVD2026-08-01
CVE-2026-7623The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored CrosMEDIUM6.411%ileNVD2026-08-01
CVE-2026-13458The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML AMEDIUM6.423%ileNVD2026-08-01
CVE-2026-15644The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'stMEDIUM6.411%ileNVD2026-08-01
CVE-2026-15645The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'naMEDIUM6.411%ileNVD2026-08-01
CVE-2026-15649The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ShoMEDIUM6.410%ileNVD2026-08-01
CVE-2026-15662The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-SitMEDIUM6.414%ileNVD2026-08-01
CVE-2026-15950The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPressMEDIUM6.49%ileNVD2026-08-01
CVE-2026-16090The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is MEDIUM6.49%ileNVD2026-08-01
CVE-2026-16091The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is MEDIUM6.410%ileNVD2026-08-01
CVE-2026-16684The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User ContactMEDIUM6.49%ileNVD2026-08-01
CVE-2026-16685The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute inMEDIUM6.415%ileNVD2026-08-01
CVE-2026-18062The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.411%ileNVD2026-08-01
CVE-2026-18435The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.49%ileNVD2026-08-01
CVE-2026-12231The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infoMEDIUM6.417%ileNVD2026-08-02
CVE-2026-18481Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticateMEDIUM6.220%ileNVD2026-07-31
CVE-2026-14515IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptinMEDIUM6.18%ileNVD2026-07-28
CVE-2026-65946Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0MEDIUM6.15%ileNVD2026-07-29
CVE-2026-66490Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2MEDIUM6.15%ileNVD2026-07-29
CVE-2025-65337Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address MEDIUM6.15%ileNVD2026-07-29
CVE-2026-17797Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.18%ileNVD2026-07-30
CVE-2026-17818Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbiMEDIUM6.17%ileNVD2026-07-30
CVE-2026-17827Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.17%ileNVD2026-07-30
CVE-2026-17845Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.18%ileNVD2026-07-30
CVE-2026-17853Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comprMEDIUM6.17%ileNVD2026-07-30
CVE-2026-17878Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.17%ileNVD2026-07-30
CVE-2026-17962Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrMEDIUM6.17%ileNVD2026-07-30
CVE-2026-11881The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settingMEDIUM6.18%ileNVD2026-07-30
CVE-2026-13330The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adMEDIUM6.18%ileNVD2026-07-30
CVE-2026-14207The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field beforMEDIUM6.19%ileNVD2026-07-30
CVE-2026-14592The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks beforMEDIUM6.111%ileNVD2026-07-30
CVE-2025-0152IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1MEDIUM6.16%ileNVD2026-07-30
CVE-2025-51684CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data MEDIUM6.112%ileNVD2026-07-30
CVE-2025-65341Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.MEDIUM6.15%ileNVD2026-07-30
CVE-2025-65342code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.MEDIUM6.15%ileNVD2026-07-30
CVE-2026-61526AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 throughMEDIUM6.19%ileNVD2026-07-30
CVE-2026-14845The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor reMEDIUM6.16%ileNVD2026-07-31
CVE-2026-14921The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_MEDIUM6.15%ileNVD2026-07-31
CVE-2026-14922WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 througMEDIUM6.15%ileNVD2026-07-31
CVE-2026-52232A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D BuildMEDIUM6.15%ileNVD2026-07-31
CVE-2026-17571The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulneMEDIUM6.111%ileNVD2026-08-01
CVE-2026-18344The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parMEDIUM6.112%ileNVD2026-08-01
CVE-2026-14841The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refleMEDIUM6.18%ileNVD2026-08-02
CVE-2026-13340The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extMEDIUM6.18%ileNVD2026-08-03
CVE-2026-15383The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whicMEDIUM6.16%ileNVD2026-08-03
CVE-2026-15931The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthentMEDIUM6.16%ileNVD2026-08-03
CVE-2026-38444osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value isMEDIUM6.123%ileNVD2026-08-03
CVE-2026-38446A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread eMEDIUM6.116%ileNVD2026-08-03
CVE-2026-10032The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the UMEDIUM6.1NVD2026-08-04
CVE-2026-17728Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject aMEDIUM5.48%ileNVD2026-07-30
CVE-2026-17734Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbMEDIUM5.48%ileNVD2026-07-30
CVE-2026-17903Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local nMEDIUM5.42%ileNVD2026-07-30
CVE-2025-36298IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0MEDIUM5.46%ileNVD2026-07-30
CVE-2025-36431IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulneraMEDIUM5.46%ileNVD2026-07-30
CVE-2026-11383IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scriMEDIUM5.46%ileNVD2026-07-30
CVE-2026-62324Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElemMEDIUM5.48%ileNVD2026-07-31
CVE-2026-12696The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inMEDIUM5.43%ileNVD2026-08-01
CVE-2026-14292The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in tMEDIUM5.46%ileNVD2026-08-01
CVE-2026-15234The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usinMEDIUM5.43%ileNVD2026-08-01
CVE-2026-15262The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outMEDIUM5.43%ileNVD2026-08-01
CVE-2026-14864The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its sMEDIUM5.43%ileNVD2026-08-02
CVE-2026-15385The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-mMEDIUM5.43%ileNVD2026-08-02
CVE-2026-16063The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline contMEDIUM5.43%ileNVD2026-08-02
CVE-2026-14192Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software andMEDIUM5.47%ileNVD2026-08-04
CVE-2026-59232Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding MEDIUM5.323%ileNVD2026-07-31
CVE-2026-46594A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicioMEDIUM5.128%ileNVD2026-07-31
CVE-2025-71404better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the MEDIUM5.133%ileNVD2026-08-01
CVE-2026-67333better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of rediMEDIUM5.15%ileNVD2026-08-01
CVE-2026-67338JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to valiMEDIUM5.17%ileNVD2026-08-01
CVE-2026-68583luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field thMEDIUM5.14%ileNVD2026-08-02
CVE-2026-66296Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sitMEDIUM5.123%ileNVD2026-08-03
CVE-2026-49131OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firMEDIUM5.16%ileNVD2026-08-03
CVE-2026-49132OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injecMEDIUM5.12%ileNVD2026-08-03
CVE-2026-67196Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inMEDIUM5.1NVD2026-08-04
CVE-2026-15920An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(MEDIUM5.1NVD2026-08-04
CVE-2026-13344The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing TaMEDIUM4.87%ileNVD2026-07-30
CVE-2026-34495Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FMEDIUM4.834%ileNVD2026-07-31
CVE-2026-34497Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM SysteMEDIUM4.834%ileNVD2026-07-31
CVE-2025-15669The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before renMEDIUM4.87%ileNVD2026-08-01
CVE-2025-15675The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields beforMEDIUM4.87%ileNVD2026-08-02
CVE-2026-67612OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that alMEDIUM4.84%ileNVD2026-08-03
CVE-2026-67617Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that alMEDIUM4.86%ileNVD2026-08-03
CVE-2026-3093GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1MEDIUM4.715%ileNVD2026-07-29
CVE-2026-16273The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field MEDIUM4.63%ileNVD2026-08-02
CVE-2026-14337Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a useMEDIUM4.6NVD2026-08-04
CVE-2026-17739Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced MEDIUM4.24%ileNVD2026-07-30
CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT BrowseMEDIUM4.26%ileNVD2026-07-30
CVE-2026-13393The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-itemLOW3.54%ileNVD2026-07-31
CVE-2026-18682A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /apiLOW1.316%ileNVD2026-08-03
CVE-2026-14239The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken froUNKNOWN3%ileNVD2026-07-30
CVE-2026-13725The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user UNKNOWN7%ileNVD2026-08-01
CVE-2026-52520Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/UNKNOWN10%ileNVD2026-08-03
FG-IR-26-149Cross-Site Scripting in Domain parameterUNKNOWNFortinet2026-07-14
FG-IR-26-150SSL-VPN Reflected XSSUNKNOWNFortinet2026-07-14
FG-IR-26-110Multiple Stored XSSUNKNOWNFortinet2026-04-14