CVE z tagiem xss — 200 wyników. ← Wszystkie tagi

CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2014-2120 🔴 Łataj teraz KEV
network

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug I…

6.1 CVSS
69.8% EPSS
ciscoxss 2014-03-19
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2025-48700 🔴 Łataj teraz KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user…

6.1 CVSS
22.4% EPSS
synacorxss 2025-06-23
CVE-2025-66376 🔴 Łataj teraz KEV

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

7.2 CVSS
11.4% EPSS
synacorxss 2026-01-05
CVE-2012-0767 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on A…

6.1 CVSS
14.9% EPSS
adobexss 2012-02-16
CVE-2026-42897 🔴 Łataj teraz KEV
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

8.1 CVSS
2.5% EPSS
microsoftxss 2026-05-14
CVE-2024-44309 🔴 Łataj teraz KEV
os

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing m…

6.3 CVSS
1.3% EPSS
applexss 2024-11-20
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-28741 🟠 Łataj w tym tygodniu

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

8.8 CVSS
86.4% EPSS
xss 2024-04-06
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2023-3388 🟡 Monitoruj

The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and …

7.2 CVSS
59.1% EPSS
CVE-2023-0084 🟡 Monitoruj

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and outp…

7.2 CVSS
47.8% EPSS
wpmetxss 2023-03-02
CVE-2023-1080 ⚪ Do wiadomości

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes…

6.1 CVSS
44.7% EPSS
gnpublisherxss 2023-02-28
CVE-2023-0992 🟡 Monitoruj

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject …

7.2 CVSS
38.8% EPSS
CVE-2016-7981 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

6.1 CVSS
43.5% EPSS
spipxss 2017-01-18
CVE-2010-0494 ⚪ Do wiadomości
appscloud

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume…

4.3 CVSS
50.2% EPSS
microsoftxss 2010-03-31
CVE-2023-0942 ⚪ Do wiadomości

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escapin…

6.1 CVSS
40.0% EPSS
artisanworkshopxss 2023-02-21
CVE-2006-3436 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack proper…

4.3 CVSS
48.6% EPSS
microsoftxss 2006-10-10
CVE-2024-2194 🟡 Monitoruj

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This…

7.2 CVSS
27.8% EPSS
xss 2024-03-13
CVE-2019-25152 🟡 Monitoruj

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.…

7.2 CVSS
27.1% EPSS
CVE-2006-5152 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an…

6.8 CVSS
27.2% EPSS
microsoftxss 2006-10-05
CVE-2024-47374 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a …

7.1 CVSS
21.0% EPSS
litespeedtechxss 2024-10-05
CVE-2022-45365 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

7.1 CVSS
20.1% EPSS
urosevicxss 2023-12-14
CVE-2020-36731 🟡 Monitoruj

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. Th…

7.2 CVSS
19.5% EPSS
wpdeskexploitxss 2023-06-07
CVE-2024-30194 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
18.7% EPSS
CVE-2024-29137 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

7.1 CVSS
16.9% EPSS
themeficxss 2024-03-19
CVE-2024-35693 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= …

7.1 CVSS
16.9% EPSS
code4recoveryxss 2024-06-08
CVE-2024-35694 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

7.1 CVSS
16.8% EPSS
amaurixss 2024-06-08
CVE-2010-0440 ⚪ Do wiadomości
network

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers…

4.3 CVSS
30.6% EPSS
ciscoexploitxss 2010-02-03
CVE-2026-45087 🟠 Łataj w tym tygodniu

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no…

10.0 CVSS
0.1% EPSS
xss 2026-05-27
CVE-2026-50551 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remo…

9.9 CVSS
0.4% EPSS
rcexss 2026-06-24
CVE-2024-29792 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor…

7.1 CVSS
14.4% EPSS
CVE-2006-5114 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command paramet…

6.8 CVSS
15.8% EPSS
sapexploitxss 2006-10-03
CVE-2026-54067 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via insertAdjacentHTML. A…

9.9 CVSS
0.3% EPSS
rcexss 2026-06-24
CVE-2026-54158 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsse…

9.9 CVSS
0.3% EPSS
rcexss 2026-06-24
CVE-2026-34571 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerab…

9.9 CVSS
0.1% EPSS
CVE-2026-34569 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.9 CVSS
0.0% EPSS
CVE-2026-25200 🟠 Łataj w tym tygodniu

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.…

9.8 CVSS
0.5% EPSS
samsungxss 2026-02-02
CVE-2026-53787 🟠 Łataj w tym tygodniu

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by …

9.8 CVSS
0.2% EPSS
CVE-2024-37261 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <…

7.1 CVSS
13.7% EPSS
wplabxss 2024-07-22
CVE-2026-1615 🟠 Łataj w tym tygodniu

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path inp…

9.8 CVSS
0.1% EPSS
rcexss 2026-02-09
CVE-2025-14320 🟠 Łataj w tym tygodniu

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS. Th…

9.8 CVSS
0.1% EPSS
xss 2026-05-04
CVE-2024-3166 🔴 Łataj teraz

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the appli…

9.6 CVSS
1.0% EPSS
CVE-2015-6477 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors…

6.1 CVSS
18.0% EPSS
nordexxss 2015-10-18
CVE-2026-56395 🟠 Łataj w tym tygodniu

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code executio…

9.6 CVSS
0.4% EPSS
rcexss 2026-06-21
CVE-2026-56397 🟠 Łataj w tym tygodniu

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code executio…

9.6 CVSS
0.4% EPSS
rcexss 2026-06-21
CVE-2024-29931 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

7.1 CVSS
12.9% EPSS
codecabinxss 2024-03-27
CVE-2025-66562 🟠 Łataj w tym tygodniu

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Mar…

9.6 CVSS
0.2% EPSS
aiqlrcexss 2025-12-05
CVE-2026-53662 🟠 Łataj w tym tygodniu

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully c…

9.6 CVSS
0.2% EPSS
xss 2026-06-23
CVE-2026-42090 🟠 Łataj w tym tygodniu

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow ca…

9.6 CVSS
0.2% EPSS
streetwritersrcexss 2026-05-04
CVE-2026-32626 🔴 Łataj teraz

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the c…

9.6 CVSS
0.2% EPSS
CVE-2026-33976 🔴 Łataj teraz

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root caus…

9.6 CVSS
0.1% EPSS
CVE-2026-33334 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `conte…

9.6 CVSS
0.1% EPSS
vikunjarcexss 2026-03-24
CVE-2026-32890 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web da…

9.6 CVSS
0.1% EPSS
openvesslxss 2026-03-20
CVE-2026-1115 🔴 Łataj teraz

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backe…

9.6 CVSS
0.1% EPSS
lollmsexploitxss 2026-04-10
CVE-2025-69771 🟠 Łataj w tym tygodniu

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform …

9.6 CVSS
0.0% EPSS
killergerbahxss 2026-02-25
CVE-2023-5538 🟡 Monitoruj

The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This ma…

7.2 CVSS
11.2% EPSS
mrpengexploitxss 2023-10-18
CVE-2024-37259 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit …

7.1 CVSS
11.7% EPSS
wpextendedxss 2024-07-22
CVE-2006-5661 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

6.8 CVSS
13.1% EPSS
virtechexploitxss 2006-11-03
CVE-2024-29138 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Restrict User Access – Membership Plugin with Force restrict-user-access.This issue affects Restrict Us…

7.1 CVSS
11.6% EPSS
dev.institutexss 2024-03-19
CVE-2025-8668 🟠 Łataj w tym tygodniu

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows…

9.4 CVSS
0.0% EPSS
xss 2026-02-11
CVE-2026-44990 🟠 Łataj w tym tygodniu

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can tur…

9.3 CVSS
0.3% EPSS
xss 2026-06-12
CVE-2026-12048 🟠 Łataj w tym tygodniu

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist er…

9.3 CVSS
0.3% EPSS
pgadminxss 2026-06-19
CVE-2026-48768 🟠 Łataj w tym tygodniu

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issu…

9.3 CVSS
0.3% EPSS
xss 2026-06-18
CVE-2022-1707 ⚪ Do wiadomości

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization …

6.1 CVSS
16.2% EPSS
gtm4wpxss 2022-06-13
CVE-2026-27243 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27245 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27246 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScr…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-34691 🟠 Łataj w tym tygodniu

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …

9.3 CVSS
0.1% EPSS
adobexss 2026-06-09
CVE-2026-32754 🔴 Łataj teraz

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming…

9.3 CVSS
0.1% EPSS
freescoutexploitxss 2026-03-19
CVE-2026-32940 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses data:text/xml and dat…

9.3 CVSS
0.1% EPSS
b3logexploitxss 2026-03-20
CVE-2026-44212 🟠 Łataj w tym tygodniu

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attack…

9.3 CVSS
0.1% EPSS
xss 2026-05-14
CVE-2026-33135 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-33136 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaSc…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-31845 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input…

9.3 CVSS
0.0% EPSS
xss 2026-04-11
CVE-2026-42849 🟠 Łataj w tym tygodniu

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy br…

9.3 CVSS
0.0% EPSS
goauthentikxss 2026-06-02
CVE-2026-30562 🟠 Łataj w tym tygodniu

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanit…

9.3 CVSS
0.0% EPSS
xss 2026-03-30
CVE-2026-43900 🟠 Łataj w tym tygodniu

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend…

9.3 CVSS
0.0% EPSS
xss 2026-05-11
CVE-2023-0968 ⚪ Do wiadomości

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and…

6.1 CVSS
15.8% EPSS
kibokolabsxss 2023-03-03
CVE-2006-5351 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX…

9.0 CVSS
0.7% EPSS
oraclexss 2006-10-18
CVE-2025-66024 🔴 Łataj teraz

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arise…

9.0 CVSS
0.6% EPSS
CVE-2026-34558 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-34557 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-34563 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34564 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34565 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34566 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34567 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34568 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-41201 🟠 Łataj w tym tygodniu

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege…

9.1 CVSS
0.0% EPSS
CVE-2026-34560 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application renders user-controlled input unsaf…

9.1 CVSS
0.0% EPSS
CVE-2026-34559 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-24769 🔴 Łataj teraz

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload mali…

9.0 CVSS
0.4% EPSS
nocodbexploitxss 2026-01-28
CVE-2026-55570 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of eac…

9.0 CVSS
0.3% EPSS
xss 2026-06-24
CVE-2024-43971 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
9.8% EPSS
CVE-2026-33066 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through u…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32751 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket eve…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-19
CVE-2026-39846 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption cont…

9.0 CVSS
0.1% EPSS
b3logexploitrcexss 2026-04-07
CVE-2026-33067 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject ar…

9.0 CVSS
0.1% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32635 🟠 Łataj w tym tygodniu

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulne…

9.0 CVSS
0.1% EPSS
angularxss 2026-03-16
CVE-2026-34448 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view w…

9.0 CVSS
0.1% EPSS
b3logexploitxss 2026-03-31
CVE-2026-40322 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. T…

9.0 CVSS
0.1% EPSS
b3logrcexss 2026-04-16
CVE-2026-42457 🟠 Łataj w tym tygodniu

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name …

9.0 CVSS
0.1% EPSS
xss 2026-05-14
CVE-2026-42523 🟠 Łataj w tym tygodniu
dev

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site sc…

9.0 CVSS
0.0% EPSS
jenkinsxss 2026-04-29
CVE-2026-36748 🟠 Łataj w tym tygodniu

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

9.0 CVSS
0.0% EPSS
xss 2026-06-03
CVE-2026-32703 🟠 Łataj w tym tygodniu

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This a…

9.0 CVSS
0.0% EPSS
openprojectxss 2026-03-18
CVE-2026-32891 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector.…

9.0 CVSS
0.0% EPSS
openvesslxss 2026-03-20
CVE-2026-52798 🟡 Monitoruj

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitiz…

8.9 CVSS
0.4% EPSS
xss 2026-06-24
CVE-2026-7569 🟡 Monitoruj

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2026-9780 🟡 Monitoruj

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2024-39646 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

7.1 CVSS
9.1% EPSS
kunalnagarxss 2024-08-01
CVE-2025-40892 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report contain…

8.9 CVSS
0.1% EPSS
nozominetworksxss 2025-12-18
CVE-2026-39328 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf…

8.9 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-38949 🟡 Monitoruj

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing inject…

8.9 CVSS
0.0% EPSS
xss 2026-04-28
CVE-2025-11956 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS. This issue affects OBS (S…

8.9 CVSS
0.0% EPSS
xss 2025-11-06
CVE-2025-10467 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Stored…

8.9 CVSS
0.0% EPSS
xss 2025-09-25
CVE-2025-9798 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS. This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

8.9 CVSS
0.0% EPSS
xss 2025-09-23
CVE-2026-43984 🟡 Monitoruj

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint w…

8.9 CVSS
0.0% EPSS
xss 2026-06-04
CVE-2026-30934 🟠 Łataj w tym tygodniu

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /publi…

8.9 CVSS
0.0% EPSS
CVE-2025-40899 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a maliciou…

8.9 CVSS
0.0% EPSS
xss 2026-04-15
CVE-2026-40487 🟡 Monitoruj

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing…

8.9 CVSS
0.0% EPSS
xss 2026-04-18
CVE-2026-42611 🟡 Monitoruj

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire sys…

8.9 CVSS
0.0% EPSS
rcexss 2026-05-11
CVE-2006-5944 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.

6.8 CVSS
10.4% EPSS
CVE-2022-2541 🟡 Monitoruj

The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/act…

8.8 CVSS
0.3% EPSS
CVE-2022-2542 🟡 Monitoruj

The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/…

8.8 CVSS
0.3% EPSS
CVE-2026-3533 🟡 Monitoruj

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function …

8.8 CVSS
0.3% EPSS
rcexss 2026-03-24
CVE-2026-32208 🟡 Monitoruj
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.

8.8 CVSS
0.3% EPSS
microsoftxss 2026-06-19
CVE-2026-33336 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not…

8.8 CVSS
0.3% EPSS
CVE-2022-2540 🟡 Monitoruj

The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function …

8.8 CVSS
0.2% EPSS
CVE-2025-57151 🟠 Łataj w tym tygodniu

phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.

8.8 CVSS
0.1% EPSS
CVE-2026-1819 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 2301202…

8.8 CVSS
0.1% EPSS
xss 2026-02-04
CVE-2006-5975 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

6.8 CVSS
10.1% EPSS
drumsterexploitxss 2006-11-20
CVE-2026-33506 🟠 Łataj w tym tygodniu

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis's login…

8.8 CVSS
0.1% EPSS
oryexploitxss 2026-03-26
CVE-2026-33510 🟠 Łataj w tym tygodniu

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl),…

8.8 CVSS
0.1% EPSS
homarrexploitxss 2026-04-06
CVE-2026-32207 🟡 Monitoruj
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

8.8 CVSS
0.1% EPSS
microsoftxss 2026-05-07
CVE-2026-33124 🟡 Monitoruj

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current passwo…

8.8 CVSS
0.0% EPSS
frigatexss 2026-03-20
CVE-2026-3220 🟡 Monitoruj

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a pr…

8.8 CVSS
0.0% EPSS
xss 2026-05-18
CVE-2026-7498 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue aff…

8.8 CVSS
0.0% EPSS
xss 2026-05-18
CVE-2026-3953 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. T…

8.8 CVSS
0.0% EPSS
xss 2026-05-07
CVE-2026-5784 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 be…

8.8 CVSS
0.0% EPSS
xss 2026-05-07
CVE-2026-6002 🟡 Monitoruj

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4…

8.8 CVSS
0.0% EPSS
xss 2026-05-07
CVE-2026-55237 🟡 Monitoruj

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's s…

8.8 CVSS
0.0% EPSS
xss 2026-06-18
CVE-2026-25759 🟡 Monitoruj

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject mali…

8.7 CVSS
0.3% EPSS
statamicxss 2026-02-11
CVE-2026-53608 🟡 Monitoruj

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Ma…

8.7 CVSS
0.2% EPSS
xss 2026-06-12
CVE-2026-24665 🟠 Łataj w tym tygodniu

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious …

8.7 CVSS
0.2% EPSS
gunetexploitxss 2026-02-03
CVE-2024-2834 🟡 Monitoruj

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

8.7 CVSS
0.1% EPSS
xss 2024-04-08
CVE-2026-33348 🟠 Łataj w tym tygodniu

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form …

8.7 CVSS
0.1% EPSS
open-emrexploitxss 2026-03-25
CVE-2026-30587 🟠 Łataj w tym tygodniu

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properl…

8.7 CVSS
0.1% EPSS
seafileexploitxss 2026-03-25
CVE-2026-41147 🟡 Monitoruj

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The appli…

8.7 CVSS
0.1% EPSS
xss 2026-05-22
CVE-2026-49368 🟡 Monitoruj

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

8.7 CVSS
0.1% EPSS
jetbrainsxss 2026-05-29
CVE-2026-33346 🟠 Łataj w tym tygodniu

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a pat…

8.7 CVSS
0.0% EPSS
open-emrexploitxss 2026-03-19
CVE-2026-34748 🟡 Monitoruj

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with …

8.7 CVSS
0.0% EPSS
payloadcmsxss 2026-04-01
CVE-2026-34617 🟡 Monitoruj

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject …

8.7 CVSS
0.0% EPSS
CVE-2026-45392 🟡 Monitoruj

DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a crafted URL and interacti…

8.7 CVSS
0.0% EPSS
xss 2026-05-12
CVE-2026-34241 🟡 Monitoruj

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($new…

8.7 CVSS
0.0% EPSS
xss 2026-05-19
CVE-2026-41031 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the appli…

8.7 CVSS
0.0% EPSS
xss 2026-06-09
CVE-2026-32277 🟡 Monitoruj

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 con…

8.7 CVSS
0.0% EPSS
CVE-2025-10553 🟡 Monitoruj

A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execut…

8.7 CVSS
0.0% EPSS
3dsxss 2026-03-31
CVE-2026-35576 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-39332 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of a…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-39333 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding fo…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-35169 🟡 Monitoruj

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of …

8.7 CVSS
0.0% EPSS
mcgillxss 2026-04-08
CVE-2025-10551 🟡 Monitoruj

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execut…

8.7 CVSS
0.0% EPSS
3dsxss 2026-03-31
CVE-2026-35569 🟠 Łataj w tym tygodniu

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controll…

8.7 CVSS
0.0% EPSS
CVE-2026-44667 🟡 Monitoruj

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. U…

8.7 CVSS
0.0% EPSS
xss 2026-05-26
CVE-2026-44669 🟡 Monitoruj

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied f…

8.7 CVSS
0.0% EPSS
xss 2026-05-26
CVE-2026-42197 🟡 Monitoruj

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScrip…

8.7 CVSS
0.0% EPSS
xss 2026-05-27
CVE-2026-47759 🟡 Monitoruj

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to …

8.7 CVSS
0.0% EPSS
tinyxss 2026-05-28
CVE-2026-47760 🟡 Monitoruj

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can …

8.7 CVSS
0.0% EPSS
tinyxss 2026-05-28
CVE-2026-47761 🟡 Monitoruj

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are …

8.7 CVSS
0.0% EPSS
tinyxss 2026-05-28
CVE-2026-47762 🟡 Monitoruj

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execut…

8.7 CVSS
0.0% EPSS
tinyxss 2026-05-28
CVE-2026-48527 🟡 Monitoruj

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authen…

8.7 CVSS
0.0% EPSS
xss 2026-05-29
CVE-2026-9024 🟡 Monitoruj

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to exe…

8.7 CVSS
0.0% EPSS
xss 2026-06-01
CVE-2026-33172 🟡 Monitoruj

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to by…

8.7 CVSS
0.0% EPSS
statamicxss 2026-03-20
CVE-2026-34686 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

8.7 CVSS
0.0% EPSS
adobexss 2026-05-12
CVE-2025-4123 🟡 Monitoruj

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will exec…

7.6 CVSS
5.3% EPSS
CVE-2023-6600 🟡 Monitoruj

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings…

8.6 CVSS
0.2% EPSS
daanxss 2024-01-03
CVE-2025-6397 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Software allows Reflected XSS. This issue affects Website Software: thro…

8.6 CVSS
0.1% EPSS
xss 2026-02-03
CVE-2026-34585 🟠 Łataj w tym tygodniu

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special chara…

8.6 CVSS
0.1% EPSS
b3logexploitrcexss 2026-03-31
CVE-2026-33955 🟠 Łataj w tym tygodniu

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. Th…

8.6 CVSS
0.1% EPSS
CVE-2025-7799 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-T…

8.6 CVSS
0.0% EPSS
xss 2026-02-09
CVE-2026-32721 🟡 Monitoruj

LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without…

8.6 CVSS
0.0% EPSS
openwrtxss 2026-03-19
CVE-2026-42612 🟡 Monitoruj

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue arises from a blackli…

8.5 CVSS
0.0% EPSS
xss 2026-05-11
CVE-2026-41098 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

8.4 CVSS
0.1% EPSS
xss 2026-06-09
CVE-2026-6824 🟡 Monitoruj

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, …

8.4 CVSS
0.0% EPSS
xss 2026-05-29
CVE-2024-28734 ⚪ Do wiadomości

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

6.1 CVSS
11.3% EPSS
xss 2024-03-19
CVE-2024-22397 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScrip…

8.3 CVSS
0.2% EPSS
xss 2024-03-14
CVE-2006-5524 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

6.8 CVSS
7.7% EPSS
phplistexploitxss 2006-10-26
CVE-2025-10913 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Cross-Site Scripting (XSS). This issue affec…

8.3 CVSS
0.1% EPSS
xss 2026-02-11
CVE-2026-44586 🟡 Monitoruj

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the…

8.3 CVSS
0.1% EPSS
xss 2026-05-14
CVE-2026-34780 🟡 Monitoruj

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-…

8.3 CVSS
0.0% EPSS
electronjsxss 2026-04-04
CVE-2026-21821 🟡 Monitoruj

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to…

8.3 CVSS
0.0% EPSS
xss 2026-05-13
CVE-2026-56785 🟡 Monitoruj

FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrar…

8.2 CVSS
0.2% EPSS
xss 2026-06-23
CVE-2026-25847 🟡 Monitoruj

In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

8.2 CVSS
0.2% EPSS
jetbrainsxss 2026-02-09
CVE-2025-0984 🟡 Monitoruj

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netoloji Software E-Flow allows Accessing Functionality Not Pr…

8.2 CVSS
0.1% EPSS
xss 2025-05-06
CVE-2024-2050 🟡 Monitoruj

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the prod…

8.2 CVSS
0.1% EPSS
xss 2024-03-18
CVE-2019-25676 🟠 Łataj w tym tygodniu

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags throu…

8.2 CVSS
0.1% EPSS
CVE-2020-37243 🟡 Monitoruj

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also c…

8.2 CVSS
0.1% EPSS
sql-injectionxss 2026-05-16
CVE-2026-32278 🟡 Monitoruj

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file…

8.2 CVSS
0.0% EPSS