269 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-54053 | Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl | CRITICAL | 9.6 | 52%ile | NVD | 2026-09-17 |
| CVE-2026-90561 | Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the cont | CRITICAL | 9.3 | 15%ile | NVD | 2026-09-13 |
| CVE-2026-90943 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering | CRITICAL | 9.3 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-15639 | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScrip | CRITICAL | 9.3 | 33%ile | NVD | 2026-09-16 |
| CVE-2026-93659 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a | CRITICAL | 9.3 | — | NVD | 2026-09-18 |
| CVE-2026-45143 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private | CRITICAL | 9.0 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-81742 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to | HIGH | 8.8 | 20%ile | NVD | 2026-09-12 |
| CVE-2026-85129 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featu | HIGH | 8.8 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-88793 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions | HIGH | 8.8 | 20%ile | NVD | 2026-09-13 |
| CVE-2026-84829 | The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an | HIGH | 8.8 | 39%ile | NVD | 2026-09-16 |
| CVE-2026-85130 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for t | HIGH | 8.8 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-87786 | The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputt | HIGH | 8.8 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-88792 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding o | HIGH | 8.8 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-85122 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor | HIGH | 8.8 | 8%ile | NVD | 2026-09-18 |
| CVE-2026-85127 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic | HIGH | 8.8 | 7%ile | NVD | 2026-09-18 |
| CVE-2026-88825 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin | HIGH | 8.8 | 7%ile | NVD | 2026-09-18 |
| CVE-2026-63459 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/ | HIGH | 8.7 | 22%ile | NVD | 2026-09-17 |
| CVE-2026-77615 | Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Op | HIGH | 8.7 | 33%ile | NVD | 2026-09-17 |
| CVE-2026-55691 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 8.6 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-92985 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock | HIGH | 8.6 | 43%ile | NVD | 2026-09-17 |
| CVE-2026-92986 | SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attack | HIGH | 8.6 | 35%ile | NVD | 2026-09-17 |
| CVE-2025-61682 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | HIGH | 8.6 | — | NVD | 2026-09-18 |
| CVE-2026-18111 | Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image | HIGH | 8.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-81894 | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-im | HIGH | 8.5 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-81896 | Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering | HIGH | 8.4 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-93456 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing | HIGH | 8.4 | 5%ile | NVD | 2026-09-18 |
| CVE-2026-90772 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without | HIGH | 8.3 | 11%ile | NVD | 2026-09-13 |
| CVE-2026-44203 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect auth | HIGH | 8.3 | 40%ile | NVD | 2026-09-15 |
| CVE-2026-78252 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 8.2 | 33%ile | NVD | 2026-09-16 |
| CVE-2026-54253 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pac | HIGH | 8.2 | 13%ile | NVD | 2026-09-17 |
| CVE-2026-83946 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori | HIGH | 8.2 | 33%ile | NVD | 2026-09-18 |
| CVE-2026-91127 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic | HIGH | 8.2 | — | NVD | 2026-09-18 |
| CVE-2026-63671 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nu | HIGH | 8.1 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-87888 | The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pri | HIGH | 8.0 | 14%ile | NVD | 2026-09-12 |
| CVE-2026-92134 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confi | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92135 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configurat | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92136 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-81897 | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not vali | HIGH | 7.7 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-85385 | Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en | HIGH | 7.7 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie | HIGH | 7.6 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-54506 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | HIGH | 7.6 | 17%ile | NVD | 2026-09-17 |
| CVE-2026-67103 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to | HIGH | 7.6 | 13%ile | NVD | 2026-09-18 |
| CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | HIGH | 7.6 | 53%ile | Microsoft | 2023-04-11 |
| CVE-2026-85189 | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 1 | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-85190 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-85191 | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joom | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-85195 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2 | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-88852 | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-88853 | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < | HIGH | 7.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-55690 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 7.5 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-55692 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 7.5 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-18113 | In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing | HIGH | 7.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-81898 | In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling | HIGH | 7.5 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-53660 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes | HIGH | 7.4 | 27%ile | NVD | 2026-09-15 |
| CVE-2026-18117 | Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because th | HIGH | 7.3 | 19%ile | NVD | 2026-09-14 |
| CVE-2026-18116 | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in | HIGH | 7.3 | 17%ile | NVD | 2026-09-14 |
| CVE-2026-81900 | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them int | HIGH | 7.3 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-81899 | Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > G | HIGH | 7.3 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-85386 | Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload quest | HIGH | 7.3 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-76154 | A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role | HIGH | 7.3 | 33%ile | NVD | 2026-09-17 |
| CVE-2023-28148 | A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520. | HIGH | 7.2 | 11%ile | NVD | 2026-09-14 |
| CVE-2026-90650 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eve | HIGH | 7.2 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-18595 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Requ | HIGH | 7.2 | 17%ile | NVD | 2026-09-16 |
| CVE-2026-83561 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm | HIGH | 7.2 | 22%ile | NVD | 2026-09-18 |
| CVE-2026-18405 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul | HIGH | 7.2 | 41%ile | NVD | 2026-09-18 |
| CVE-2026-87915 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress | HIGH | 7.2 | 40%ile | NVD | 2026-09-18 |
| CVE-2026-81429 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template | HIGH | 7.1 | 0%ile | NVD | 2026-09-12 |
| CVE-2026-86444 | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute | HIGH | 7.1 | 19%ile | NVD | 2026-09-16 |
| CVE-2025-15697 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev | HIGH | 7.1 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-91014 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its | HIGH | 7.1 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-90887 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | HIGH | 7.1 | 8%ile | NVD | 2026-09-17 |
| CVE-2026-90986 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | HIGH | 7.1 | 8%ile | NVD | 2026-09-17 |
| CVE-2026-93485 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre | HIGH | 7.1 | 6%ile | NVD | 2026-09-18 |
| CVE-2026-18119 | Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page C | HIGH | 7.0 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-81903 | Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without valida | HIGH | 7.0 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-44793 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non | HIGH | 7.0 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-82847 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting | MEDIUM | 6.8 | 15%ile | NVD | 2026-09-12 |
| CVE-2026-83532 | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes b | MEDIUM | 6.8 | 15%ile | NVD | 2026-09-12 |
| CVE-2026-86790 | The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a | MEDIUM | 6.8 | 15%ile | NVD | 2026-09-12 |
| CVE-2026-76558 | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database | MEDIUM | 6.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-84088 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link s | MEDIUM | 6.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-86784 | The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befo | MEDIUM | 6.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-92140 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in | MEDIUM | 6.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-86788 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the s | MEDIUM | 6.8 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-91011 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites | MEDIUM | 6.8 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-84902 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when | MEDIUM | 6.8 | 6%ile | NVD | 2026-09-18 |
| CVE-2026-88993 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it | MEDIUM | 6.8 | 5%ile | NVD | 2026-09-18 |
| CVE-2026-62110 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-62111 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-62138 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | MEDIUM | 6.5 | 3%ile | NVD | 2026-09-11 |
| CVE-2026-88618 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This | MEDIUM | 6.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-66572 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66573 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66574 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66576 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66577 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66578 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66579 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-66617 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-78294 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | MEDIUM | 6.5 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-21512 | Azure DevOps Server Cross-Site Scripting Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-02-10 |
| CVE-2026-54165 | Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click st | MEDIUM | 6.4 | 24%ile | NVD | 2026-09-11 |
| CVE-2026-10148 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via m | MEDIUM | 6.4 | 17%ile | NVD | 2026-09-12 |
| CVE-2026-4103 | Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered w | MEDIUM | 6.4 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-85575 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widg | MEDIUM | 6.4 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-15402 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S | MEDIUM | 6.4 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-18063 | The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter i | MEDIUM | 6.4 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-15609 | The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via | MEDIUM | 6.4 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-12749 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent | MEDIUM | 6.4 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-12750 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent | MEDIUM | 6.4 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-11996 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Fie | MEDIUM | 6.4 | 11%ile | NVD | 2026-09-16 |
| CVE-2026-5920 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' para | MEDIUM | 6.4 | 14%ile | NVD | 2026-09-16 |
| CVE-2026-86311 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | 10%ile | NVD | 2026-09-17 |
| CVE-2026-2585 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para | MEDIUM | 6.4 | 5%ile | NVD | 2026-09-18 |
| CVE-2026-14855 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all | MEDIUM | 6.4 | 10%ile | NVD | 2026-09-18 |
| CVE-2026-15650 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S | MEDIUM | 6.4 | 12%ile | NVD | 2026-09-18 |
| CVE-2026-75016 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client | MEDIUM | 6.4 | 10%ile | NVD | 2026-09-18 |
| CVE-2026-84909 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri | MEDIUM | 6.4 | 15%ile | NVD | 2026-09-18 |
| CVE-2026-14472 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co | MEDIUM | 6.4 | 18%ile | NVD | 2026-09-18 |
| CVE-2026-17586 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img | MEDIUM | 6.4 | 24%ile | NVD | 2026-09-18 |
| CVE-2026-92622 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode | MEDIUM | 6.4 | 16%ile | NVD | 2026-09-18 |
| CVE-2026-15797 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress | MEDIUM | 6.4 | 37%ile | NVD | 2026-09-18 |
| CVE-2026-73169 | Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip | MEDIUM | 6.3 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-77490 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) | MEDIUM | 6.1 | 23%ile | NVD | 2026-09-11 |
| CVE-2026-79035 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 | MEDIUM | 6.1 | 9%ile | NVD | 2026-09-11 |
| CVE-2023-51769 | Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages. | MEDIUM | 6.1 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-78318 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. | MEDIUM | 6.1 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-55847 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js | MEDIUM | 6.1 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-13276 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 | MEDIUM | 6.1 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-62280 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoin | MEDIUM | 6.1 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-39038 | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (tru | MEDIUM | 6.1 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-51133 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to e | MEDIUM | 6.1 | 57%ile | NVD | 2026-09-15 |
| CVE-2026-88743 | Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags. | MEDIUM | 6.1 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-18555 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Refl | MEDIUM | 6.1 | 14%ile | NVD | 2026-09-16 |
| CVE-2026-88976 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0. | MEDIUM | 6.1 | 17%ile | NVD | 2026-09-16 |
| CVE-2026-20309 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic | MEDIUM | 6.1 | 9%ile | NVD | 2026-09-16 |
| CVE-2021-3030 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme G | MEDIUM | 6.1 | 29%ile | NVD | 2026-09-17 |
| CVE-2026-54521 | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP | MEDIUM | 6.1 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-54644 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip | MEDIUM | 6.1 | 63%ile | NVD | 2026-09-17 |
| CVE-2026-89330 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for | MEDIUM | 6.1 | 12%ile | NVD | 2026-09-18 |
| CVE-2026-92561 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in | MEDIUM | 6.1 | 14%ile | NVD | 2026-09-18 |
| CVE-2026-11757 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec | MEDIUM | 6.1 | 8%ile | NVD | 2026-09-18 |
| CVE-2026-90981 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting | MEDIUM | 6.1 | 20%ile | NVD | 2026-09-18 |
| CVE-2026-92249 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i | MEDIUM | 6.1 | 19%ile | NVD | 2026-09-18 |
| CVE-2026-92554 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte | MEDIUM | 6.1 | 19%ile | NVD | 2026-09-18 |
| CVE-2026-79294 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2025-36147 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross- | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-1025 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-1031 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-1037 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-77606 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-77607 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-77608 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-77610 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-77616 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-84992 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2026-93432 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails | MEDIUM | 6.1 | — | NVD | 2026-09-18 |
| CVE-2023-28313 | Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | MEDIUM | 6.1 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2026-81911 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templ | MEDIUM | 5.8 | 28%ile | NVD | 2026-09-11 |
| CVE-2026-76704 | A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticate | MEDIUM | 5.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2025-63842 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote | MEDIUM | 5.4 | 11%ile | NVD | 2026-09-14 |
| CVE-2024-23176 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss | MEDIUM | 5.4 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-54181 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 5.4 | 22%ile | NVD | 2026-09-14 |
| CVE-2026-91021 | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share ren | MEDIUM | 5.4 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-16186 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-78415 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-7884 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their | MEDIUM | 5.4 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-86898 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO | MEDIUM | 5.4 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-85657 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu | MEDIUM | 5.4 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-84397 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low- | MEDIUM | 5.4 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-92991 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variou | MEDIUM | 5.4 | 22%ile | NVD | 2026-09-18 |
| CVE-2026-15004 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc | MEDIUM | 5.4 | 16%ile | NVD | 2026-09-18 |
| CVE-2026-40534 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Sy | MEDIUM | 5.4 | 11%ile | NVD | 2026-09-18 |
| CVE-2026-90884 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v | MEDIUM | 5.4 | 13%ile | NVD | 2026-09-18 |
| CVE-2026-1029 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 5.4 | — | NVD | 2026-09-18 |
| CVE-2025-49745 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2025-08-12 |
| CVE-2026-90443 | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate e | MEDIUM | 5.3 | 25%ile | NVD | 2026-09-11 |
| CVE-2026-90527 | A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admi | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-13 |
| CVE-2026-90571 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-13 |
| CVE-2026-90583 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected | MEDIUM | 5.3 | 21%ile | NVD | 2026-09-13 |
| CVE-2026-85196 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere ex | MEDIUM | 5.3 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-91146 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, a | MEDIUM | 5.3 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-90848 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component St | MEDIUM | 5.3 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-91922 | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/pa | MEDIUM | 5.3 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-92584 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticat | MEDIUM | 5.3 | 11%ile | NVD | 2026-09-16 |
| CVE-2026-92973 | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that f | MEDIUM | 5.3 | 14%ile | NVD | 2026-09-17 |
| CVE-2026-54355 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu | MEDIUM | 5.3 | 33%ile | NVD | 2026-09-17 |
| CVE-2024-27123 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t | MEDIUM | 5.2 | 3%ile | NVD | 2026-09-18 |
| CVE-2026-81917 | Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the | MEDIUM | 5.1 | 29%ile | NVD | 2026-09-11 |
| CVE-2026-89268 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping | MEDIUM | 5.1 | 7%ile | NVD | 2026-09-12 |
| CVE-2026-90528 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality o | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90529 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90563 | A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the fil | MEDIUM | 5.1 | 11%ile | NVD | 2026-09-13 |
| CVE-2026-90564 | A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatM | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90567 | A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function | MEDIUM | 5.1 | 26%ile | NVD | 2026-09-13 |
| CVE-2026-90568 | A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSor | MEDIUM | 5.1 | 24%ile | NVD | 2026-09-13 |
| CVE-2026-90602 | A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is t | MEDIUM | 5.1 | 27%ile | NVD | 2026-09-13 |
| CVE-2026-82773 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this v | MEDIUM | 5.1 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-82776 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary scri | MEDIUM | 5.1 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-82781 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary scr | MEDIUM | 5.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-82788 | Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be | MEDIUM | 5.1 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-82795 | SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vuln | MEDIUM | 5.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-82796 | SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, | MEDIUM | 5.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-90931 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated | MEDIUM | 5.1 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-90957 | Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains | MEDIUM | 5.1 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-87793 | The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica. | MEDIUM | 5.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-91942 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns u | MEDIUM | 5.1 | 13%ile | NVD | 2026-09-15 |
| CVE-2026-91944 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the for | MEDIUM | 5.1 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-92234 | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Res | MEDIUM | 5.1 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-76867 | Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT conf | MEDIUM | 5.1 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-76872 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL man | MEDIUM | 5.1 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-76873 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display a | MEDIUM | 5.1 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-92257 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages t | MEDIUM | 5.1 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-92214 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/c | MEDIUM | 5.1 | 18%ile | NVD | 2026-09-16 |
| CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | MEDIUM | 5.1 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields | MEDIUM | 5.1 | 4%ile | NVD | 2026-09-16 |
| CVE-2026-93296 | MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event Gene | MEDIUM | 5.1 | 26%ile | NVD | 2026-09-17 |
| CVE-2026-53555 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl | MEDIUM | 5.1 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-93454 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu | MEDIUM | 5.1 | 7%ile | NVD | 2026-09-18 |
| CVE-2026-92976 | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A | MEDIUM | 5.1 | 31%ile | NVD | 2026-09-18 |
| CVE-2026-93505 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media- | MEDIUM | 5.1 | — | NVD | 2026-09-18 |
| CVE-2026-81918 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A us | MEDIUM | 4.8 | 28%ile | NVD | 2026-09-11 |
| CVE-2026-90569 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopic | MEDIUM | 4.8 | 28%ile | NVD | 2026-09-13 |
| CVE-2026-90570 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function Adm | MEDIUM | 4.8 | 28%ile | NVD | 2026-09-13 |
| CVE-2026-82763 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerabili | MEDIUM | 4.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-82767 | Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be exe | MEDIUM | 4.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-82769 | Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary s | MEDIUM | 4.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-82771 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary scri | MEDIUM | 4.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-82790 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY | MEDIUM | 4.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-82792 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vu | MEDIUM | 4.8 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-44282 | Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electio | MEDIUM | 4.8 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-76858 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused | MEDIUM | 4.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-76864 | NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_ | MEDIUM | 4.8 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-54645 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, | MEDIUM | 4.8 | 68%ile | NVD | 2026-09-17 |
| CVE-2026-13623 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Sy | MEDIUM | 4.8 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-19619 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.7 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-55650 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 | MEDIUM | 4.4 | 3%ile | NVD | 2026-09-15 |
| CVE-2025-13533 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an | MEDIUM | 4.4 | 10%ile | NVD | 2026-09-18 |
| CVE-2026-18317 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a | MEDIUM | 4.3 | 12%ile | NVD | 2026-09-18 |
| CVE-2026-82019 | TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows u | LOW | 2.3 | 13%ile | NVD | 2026-09-14 |
| CVE-2026-68534 | Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in sto | LOW | 2.3 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-92814 | changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary marku | LOW | 2.3 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-90615 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unkn | LOW | 2.1 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-90795 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function o | LOW | 2.1 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-91854 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the fil | LOW | 2.1 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-81925 | Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages | LOW | 2.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-87031 | n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of co | LOW | 2.1 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-90489 | A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobi | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90497 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functio | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90502 | A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/ | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90604 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90694 | A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90695 | A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknow | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90696 | A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90835 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90845 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the | LOW | 2.0 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-81926 | Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupli | LOW | 2.0 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-92381 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/ | LOW | 2.0 | 24%ile | NVD | 2026-09-16 |
| CVE-2026-92418 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff | LOW | 2.0 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-90850 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown function | LOW | 1.9 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-92385 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown fun | LOW | 1.9 | 29%ile | NVD | 2026-09-16 |
| CVE-2025-64059 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is | LOW | 1.8 | 14%ile | NVD | 2026-09-13 |
| CVE-2026-81927 | Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processin | LOW | 1.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-55630 | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted | NONE | 0.0 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-88742 | Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field. | UNKNOWN | — | 10%ile | NVD | 2026-09-15 |
| CVE-2026-87632 | Chromium CVE-2026-87632: Cross-site scripting in SanitizerAPI | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| FG-IR-26-149 | Cross-Site Scripting in Domain parameter | UNKNOWN | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-150 | SSL-VPN Reflected XSS | UNKNOWN | — | — | Fortinet | 2026-07-14 |