← Back to feed Search feed

CWE-79 Cross-Site Scripting (XSS) vulnerabilities

269 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-54053Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implCRITICAL9.652%ileNVD2026-09-17
CVE-2026-90561Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the contCRITICAL9.315%ileNVD2026-09-13
CVE-2026-90943parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering CRITICAL9.315%ileNVD2026-09-14
CVE-2026-15639An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScripCRITICAL9.333%ileNVD2026-09-16
CVE-2026-93659Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and aCRITICAL9.3NVD2026-09-18
CVE-2026-45143Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private CRITICAL9.027%ileNVD2026-09-17
CVE-2026-81742The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets toHIGH8.820%ileNVD2026-09-12
CVE-2026-85129The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featuHIGH8.818%ileNVD2026-09-13
CVE-2026-88793The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actionsHIGH8.820%ileNVD2026-09-13
CVE-2026-84829The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an HIGH8.839%ileNVD2026-09-16
CVE-2026-85130The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for tHIGH8.820%ileNVD2026-09-17
CVE-2026-87786The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputtHIGH8.820%ileNVD2026-09-17
CVE-2026-88792The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding oHIGH8.820%ileNVD2026-09-17
CVE-2026-85122The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the storHIGH8.88%ileNVD2026-09-18
CVE-2026-85127The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticHIGH8.87%ileNVD2026-09-18
CVE-2026-88825The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowinHIGH8.87%ileNVD2026-09-18
CVE-2026-63459Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/HIGH8.722%ileNVD2026-09-17
CVE-2026-77615Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in OpHIGH8.733%ileNVD2026-09-17
CVE-2026-55691The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH8.622%ileNVD2026-09-15
CVE-2026-92985SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dockHIGH8.643%ileNVD2026-09-17
CVE-2026-92986SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. AttackHIGH8.635%ileNVD2026-09-17
CVE-2025-61682Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's HIGH8.6NVD2026-09-18
CVE-2026-18111Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero ImageHIGH8.523%ileNVD2026-09-15
CVE-2026-81894Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-imHIGH8.516%ileNVD2026-09-15
CVE-2026-81896Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering HIGH8.417%ileNVD2026-09-15
CVE-2026-93456django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing HIGH8.45%ileNVD2026-09-18
CVE-2026-90772Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HIGH8.311%ileNVD2026-09-13
CVE-2026-44203Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authHIGH8.340%ileNVD2026-09-15
CVE-2026-78252GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1HIGH8.233%ileNVD2026-09-16
CVE-2026-54253TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pacHIGH8.213%ileNVD2026-09-17
CVE-2026-83946Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthoriHIGH8.233%ileNVD2026-09-18
CVE-2026-91127File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applicHIGH8.2NVD2026-09-18
CVE-2026-63671MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuHIGH8.132%ileNVD2026-09-16
CVE-2026-87888The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its priHIGH8.014%ileNVD2026-09-12
CVE-2026-92134Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confiHIGH8.032%ileNVD2026-09-16
CVE-2026-92135Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuratHIGH8.032%ileNVD2026-09-16
CVE-2026-92136Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the HIGH8.032%ileNVD2026-09-16
CVE-2026-81897In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not valiHIGH7.79%ileNVD2026-09-15
CVE-2026-85385Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output enHIGH7.736%ileNVD2026-09-16
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFieHIGH7.623%ileNVD2026-09-14
CVE-2026-54506Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5HIGH7.617%ileNVD2026-09-17
CVE-2026-67103HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to HIGH7.613%ileNVD2026-09-18
CVE-2023-28309Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityHIGH7.653%ileMicrosoft2023-04-11
CVE-2026-85189Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 1HIGH7.516%ileNVD2026-09-14
CVE-2026-85190Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 HIGH7.516%ileNVD2026-09-14
CVE-2026-85191Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for JoomHIGH7.516%ileNVD2026-09-14
CVE-2026-85195Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2HIGH7.516%ileNVD2026-09-14
CVE-2026-88852Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0,HIGH7.516%ileNVD2026-09-14
CVE-2026-88853Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla <HIGH7.516%ileNVD2026-09-14
CVE-2026-55690The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH7.522%ileNVD2026-09-15
CVE-2026-55692The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH7.530%ileNVD2026-09-15
CVE-2026-18113In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing HIGH7.517%ileNVD2026-09-15
CVE-2026-81898In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enablingHIGH7.514%ileNVD2026-09-15
CVE-2026-53660Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializesHIGH7.427%ileNVD2026-09-15
CVE-2026-18117Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because thHIGH7.319%ileNVD2026-09-14
CVE-2026-18116Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in HIGH7.317%ileNVD2026-09-14
CVE-2026-81900Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them intHIGH7.34%ileNVD2026-09-14
CVE-2026-81899Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > GHIGH7.320%ileNVD2026-09-15
CVE-2026-85386Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload questHIGH7.332%ileNVD2026-09-16
CVE-2026-76154A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor roleHIGH7.333%ileNVD2026-09-17
CVE-2023-28148A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.HIGH7.211%ileNVD2026-09-14
CVE-2026-90650The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eveHIGH7.215%ileNVD2026-09-15
CVE-2026-18595The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler RequHIGH7.217%ileNVD2026-09-16
CVE-2026-83561The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CommHIGH7.222%ileNVD2026-09-18
CVE-2026-18405The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulHIGH7.241%ileNVD2026-09-18
CVE-2026-87915The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress HIGH7.240%ileNVD2026-09-18
CVE-2026-81429The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its templateHIGH7.10%ileNVD2026-09-12
CVE-2026-86444The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attributeHIGH7.119%ileNVD2026-09-16
CVE-2025-15697The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sevHIGH7.16%ileNVD2026-09-17
CVE-2026-91014The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of itsHIGH7.16%ileNVD2026-09-17
CVE-2026-90887Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.HIGH7.18%ileNVD2026-09-17
CVE-2026-90986Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.HIGH7.18%ileNVD2026-09-17
CVE-2026-93485Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPreHIGH7.16%ileNVD2026-09-18
CVE-2026-18119Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CHIGH7.024%ileNVD2026-09-14
CVE-2026-81903Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validaHIGH7.07%ileNVD2026-09-14
CVE-2026-44793Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a nonHIGH7.038%ileNVD2026-09-15
CVE-2026-82847The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputtingMEDIUM6.815%ileNVD2026-09-12
CVE-2026-83532The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes bMEDIUM6.815%ileNVD2026-09-12
CVE-2026-86790The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a MEDIUM6.815%ileNVD2026-09-12
CVE-2026-76558The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database MEDIUM6.834%ileNVD2026-09-16
CVE-2026-84088The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link sMEDIUM6.834%ileNVD2026-09-16
CVE-2026-86784The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befoMEDIUM6.834%ileNVD2026-09-16
CVE-2026-92140Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in MEDIUM6.834%ileNVD2026-09-16
CVE-2026-86788The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the sMEDIUM6.815%ileNVD2026-09-17
CVE-2026-91011The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites MEDIUM6.815%ileNVD2026-09-17
CVE-2026-84902The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check whenMEDIUM6.86%ileNVD2026-09-18
CVE-2026-88993The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting itMEDIUM6.85%ileNVD2026-09-18
CVE-2026-62110Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.MEDIUM6.56%ileNVD2026-09-11
CVE-2026-62111Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.MEDIUM6.56%ileNVD2026-09-11
CVE-2026-62138Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.MEDIUM6.53%ileNVD2026-09-11
CVE-2026-886181024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This MEDIUM6.523%ileNVD2026-09-15
CVE-2026-66572Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66573Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66574Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66576Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66577Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66578Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66579Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-66617Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-78294Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.MEDIUM6.56%ileNVD2026-09-17
CVE-2026-21512Azure DevOps Server Cross-Site Scripting VulnerabilityMEDIUM6.561%ileMicrosoft2026-02-10
CVE-2026-54165Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stMEDIUM6.424%ileNVD2026-09-11
CVE-2026-10148The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mMEDIUM6.417%ileNVD2026-09-12
CVE-2026-4103Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered wMEDIUM6.48%ileNVD2026-09-14
CVE-2026-85575The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgMEDIUM6.46%ileNVD2026-09-15
CVE-2026-15402The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to SMEDIUM6.417%ileNVD2026-09-15
CVE-2026-18063The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter iMEDIUM6.410%ileNVD2026-09-15
CVE-2026-15609The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM6.49%ileNVD2026-09-15
CVE-2026-12749IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authentMEDIUM6.417%ileNVD2026-09-15
CVE-2026-12750IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authentMEDIUM6.417%ileNVD2026-09-15
CVE-2026-11996The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' FieMEDIUM6.411%ileNVD2026-09-16
CVE-2026-5920The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' paraMEDIUM6.414%ileNVD2026-09-16
CVE-2026-86311The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site ScripMEDIUM6.410%ileNVD2026-09-17
CVE-2026-2585The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ paraMEDIUM6.45%ileNVD2026-09-18
CVE-2026-14855The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all MEDIUM6.410%ileNVD2026-09-18
CVE-2026-15650The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.412%ileNVD2026-09-18
CVE-2026-75016The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientMEDIUM6.410%ileNVD2026-09-18
CVE-2026-84909The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site ScriMEDIUM6.415%ileNVD2026-09-18
CVE-2026-14472The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block CoMEDIUM6.418%ileNVD2026-09-18
CVE-2026-17586The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_imgMEDIUM6.424%ileNVD2026-09-18
CVE-2026-92622The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' ShortcodeMEDIUM6.416%ileNVD2026-09-18
CVE-2026-15797The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress MEDIUM6.437%ileNVD2026-09-18
CVE-2026-73169Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site ScripMEDIUM6.343%ileNVD2026-09-16
CVE-2026-77490Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) MEDIUM6.123%ileNVD2026-09-11
CVE-2026-79035A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0MEDIUM6.19%ileNVD2026-09-11
CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.MEDIUM6.19%ileNVD2026-09-14
CVE-2026-78318Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. MEDIUM6.116%ileNVD2026-09-14
CVE-2026-55847Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js MEDIUM6.116%ileNVD2026-09-14
CVE-2026-13276IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 MEDIUM6.115%ileNVD2026-09-14
CVE-2026-62280Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoinMEDIUM6.112%ileNVD2026-09-15
CVE-2026-39038BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (truMEDIUM6.18%ileNVD2026-09-15
CVE-2026-51133Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to eMEDIUM6.157%ileNVD2026-09-15
CVE-2026-88743Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.MEDIUM6.118%ileNVD2026-09-15
CVE-2026-18555The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to ReflMEDIUM6.114%ileNVD2026-09-16
CVE-2026-88976Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.MEDIUM6.117%ileNVD2026-09-16
CVE-2026-20309A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticMEDIUM6.19%ileNVD2026-09-16
CVE-2021-3030Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GMEDIUM6.129%ileNVD2026-09-17
CVE-2026-54521FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMPMEDIUM6.115%ileNVD2026-09-17
CVE-2026-54644CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses stripMEDIUM6.163%ileNVD2026-09-17
CVE-2026-89330The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for MEDIUM6.112%ileNVD2026-09-18
CVE-2026-92561The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter inMEDIUM6.114%ileNVD2026-09-18
CVE-2026-11757Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics TecMEDIUM6.18%ileNVD2026-09-18
CVE-2026-90981The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site ScriptingMEDIUM6.120%ileNVD2026-09-18
CVE-2026-92249The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter iMEDIUM6.119%ileNVD2026-09-18
CVE-2026-92554The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to ReflecteMEDIUM6.119%ileNVD2026-09-18
CVE-2026-79294Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbiMEDIUM6.1NVD2026-09-18
CVE-2025-36147IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-MEDIUM6.1NVD2026-09-18
CVE-2026-1025IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-1031IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-1037IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-77606Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77607Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77608Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77610Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77616Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-84992md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()MEDIUM6.1NVD2026-09-18
CVE-2026-93432A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it failsMEDIUM6.1NVD2026-09-18
CVE-2023-28313Microsoft Dynamics 365 Customer Voice Cross-Site Scripting VulnerabilityMEDIUM6.151%ileMicrosoft2023-04-11
CVE-2023-28314Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityMEDIUM6.151%ileMicrosoft2023-04-11
CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templMEDIUM5.828%ileNVD2026-09-11
CVE-2026-76704A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticateMEDIUM5.517%ileNVD2026-09-15
CVE-2025-63842A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote MEDIUM5.411%ileNVD2026-09-14
CVE-2024-23176An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xssMEDIUM5.47%ileNVD2026-09-14
CVE-2026-54181backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM5.422%ileNVD2026-09-14
CVE-2026-91021Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renMEDIUM5.44%ileNVD2026-09-14
CVE-2026-16186IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.MEDIUM5.48%ileNVD2026-09-14
CVE-2026-78415IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing andMEDIUM5.48%ileNVD2026-09-14
CVE-2026-7884IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit theirMEDIUM5.414%ileNVD2026-09-14
CVE-2026-86898A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOMEDIUM5.49%ileNVD2026-09-14
CVE-2026-85657The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vuMEDIUM5.44%ileNVD2026-09-15
CVE-2026-84397Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-MEDIUM5.434%ileNVD2026-09-16
CVE-2026-92991The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variouMEDIUM5.422%ileNVD2026-09-18
CVE-2026-15004The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM5.416%ileNVD2026-09-18
CVE-2026-40534An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in SyMEDIUM5.411%ileNVD2026-09-18
CVE-2026-90884The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all vMEDIUM5.413%ileNVD2026-09-18
CVE-2026-1029IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM5.4NVD2026-09-18
CVE-2025-49745Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityMEDIUM5.442%ileMicrosoft2025-08-12
CVE-2026-90443A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate eMEDIUM5.325%ileNVD2026-09-11
CVE-2026-90527A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admiMEDIUM5.320%ileNVD2026-09-13
CVE-2026-90571A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functioMEDIUM5.320%ileNVD2026-09-13
CVE-2026-90583A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected MEDIUM5.321%ileNVD2026-09-13
CVE-2026-85196Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere exMEDIUM5.318%ileNVD2026-09-14
CVE-2026-91146Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, aMEDIUM5.39%ileNVD2026-09-14
CVE-2026-90848A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StMEDIUM5.318%ileNVD2026-09-15
CVE-2026-91922Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/paMEDIUM5.324%ileNVD2026-09-15
CVE-2026-92584AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticatMEDIUM5.311%ileNVD2026-09-16
CVE-2026-92973ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fMEDIUM5.314%ileNVD2026-09-17
CVE-2026-54355MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpuMEDIUM5.333%ileNVD2026-09-17
CVE-2024-27123A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit tMEDIUM5.23%ileNVD2026-09-18
CVE-2026-81917Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the MEDIUM5.129%ileNVD2026-09-11
CVE-2026-89268QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping MEDIUM5.17%ileNVD2026-09-12
CVE-2026-90528A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality oMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90529A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip ofMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90563A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the filMEDIUM5.111%ileNVD2026-09-13
CVE-2026-90564A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90567A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function MEDIUM5.126%ileNVD2026-09-13
CVE-2026-90568A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSorMEDIUM5.124%ileNVD2026-09-13
CVE-2026-90602A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is tMEDIUM5.127%ileNVD2026-09-13
CVE-2026-82773Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vMEDIUM5.19%ileNVD2026-09-14
CVE-2026-82776Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary scriMEDIUM5.19%ileNVD2026-09-14
CVE-2026-82781Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary scrMEDIUM5.14%ileNVD2026-09-14
CVE-2026-82788Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may beMEDIUM5.15%ileNVD2026-09-14
CVE-2026-82795SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnMEDIUM5.14%ileNVD2026-09-14
CVE-2026-82796SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited,MEDIUM5.14%ileNVD2026-09-14
CVE-2026-90931LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticatedMEDIUM5.17%ileNVD2026-09-14
CVE-2026-90957Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains MEDIUM5.115%ileNVD2026-09-14
CVE-2026-87793The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.MEDIUM5.134%ileNVD2026-09-15
CVE-2026-91942crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns uMEDIUM5.113%ileNVD2026-09-15
CVE-2026-91944crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forMEDIUM5.116%ileNVD2026-09-15
CVE-2026-92234QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel ResMEDIUM5.19%ileNVD2026-09-15
CVE-2026-76867Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT confMEDIUM5.18%ileNVD2026-09-15
CVE-2026-76872Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL manMEDIUM5.18%ileNVD2026-09-15
CVE-2026-76873Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display aMEDIUM5.19%ileNVD2026-09-15
CVE-2026-92257Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages tMEDIUM5.18%ileNVD2026-09-15
CVE-2026-92214A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/cMEDIUM5.118%ileNVD2026-09-16
CVE-2026-61597djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to MEDIUM5.123%ileNVD2026-09-16
CVE-2026-92590Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated FieldsMEDIUM5.14%ileNVD2026-09-16
CVE-2026-93296MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event GeneMEDIUM5.126%ileNVD2026-09-17
CVE-2026-53555SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uplMEDIUM5.130%ileNVD2026-09-17
CVE-2026-93454Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting pluMEDIUM5.17%ileNVD2026-09-18
CVE-2026-92976A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. AMEDIUM5.131%ileNVD2026-09-18
CVE-2026-93505A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-MEDIUM5.1NVD2026-09-18
CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A usMEDIUM4.828%ileNVD2026-09-11
CVE-2026-90569A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicMEDIUM4.828%ileNVD2026-09-13
CVE-2026-90570A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdmMEDIUM4.828%ileNVD2026-09-13
CVE-2026-82763Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerabiliMEDIUM4.84%ileNVD2026-09-14
CVE-2026-82767Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be exeMEDIUM4.86%ileNVD2026-09-14
CVE-2026-82769Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary sMEDIUM4.86%ileNVD2026-09-14
CVE-2026-82771Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary scriMEDIUM4.86%ileNVD2026-09-14
CVE-2026-82790Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RYMEDIUM4.84%ileNVD2026-09-14
CVE-2026-82792Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vuMEDIUM4.85%ileNVD2026-09-14
CVE-2026-44282Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electioMEDIUM4.831%ileNVD2026-09-15
CVE-2026-76858Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi causedMEDIUM4.821%ileNVD2026-09-15
CVE-2026-76864NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_MEDIUM4.810%ileNVD2026-09-15
CVE-2026-54645CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, MEDIUM4.868%ileNVD2026-09-17
CVE-2026-13623An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in SyMEDIUM4.89%ileNVD2026-09-18
CVE-2026-19619GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM4.723%ileNVD2026-09-16
CVE-2026-55650Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2MEDIUM4.43%ileNVD2026-09-15
CVE-2025-13533The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, anMEDIUM4.410%ileNVD2026-09-18
CVE-2026-18317The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to aMEDIUM4.312%ileNVD2026-09-18
CVE-2026-82019TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows uLOW2.313%ileNVD2026-09-14
CVE-2026-68534Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stoLOW2.330%ileNVD2026-09-15
CVE-2026-92814changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markuLOW2.313%ileNVD2026-09-16
CVE-2026-90615A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknLOW2.120%ileNVD2026-09-14
CVE-2026-90795A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function oLOW2.138%ileNVD2026-09-14
CVE-2026-91854A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the filLOW2.120%ileNVD2026-09-15
CVE-2026-81925Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messagesLOW2.131%ileNVD2026-09-15
CVE-2026-87031n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of coLOW2.125%ileNVD2026-09-16
CVE-2026-90489A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobiLOW2.09%ileNVD2026-09-13
CVE-2026-90497A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functioLOW2.09%ileNVD2026-09-13
CVE-2026-90502A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/LOW2.09%ileNVD2026-09-13
CVE-2026-90604A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the componentLOW2.010%ileNVD2026-09-14
CVE-2026-90694A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of theLOW2.010%ileNVD2026-09-14
CVE-2026-90695A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknowLOW2.010%ileNVD2026-09-14
CVE-2026-90696A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknownLOW2.010%ileNVD2026-09-14
CVE-2026-90835A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the LOW2.010%ileNVD2026-09-14
CVE-2026-90845A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the LOW2.010%ileNVD2026-09-15
CVE-2026-81926Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupliLOW2.024%ileNVD2026-09-15
CVE-2026-92381A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/LOW2.024%ileNVD2026-09-16
CVE-2026-92418A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affLOW2.026%ileNVD2026-09-16
CVE-2026-90850A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionLOW1.912%ileNVD2026-09-15
CVE-2026-92385A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown funLOW1.929%ileNVD2026-09-16
CVE-2025-64059Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is LOW1.814%ileNVD2026-09-13
CVE-2026-81927Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processinLOW1.824%ileNVD2026-09-15
CVE-2026-55630Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted NONE0.025%ileNVD2026-09-15
CVE-2026-88742Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.UNKNOWN10%ileNVD2026-09-15
CVE-2026-87632Chromium CVE-2026-87632: Cross-site scripting in SanitizerAPIUNKNOWN14%ileMicrosoft2026-09-08
FG-IR-26-149Cross-Site Scripting in Domain parameterUNKNOWNFortinet2026-07-14
FG-IR-26-150SSL-VPN Reflected XSSUNKNOWNFortinet2026-07-14