CVE z tagiem xss — 200 wyników. ← Wszystkie tagi

CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2014-2120 🔴 Łataj teraz KEV
network

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug I…

6.1 CVSS
69.8% EPSS
ciscoxss 2014-03-19
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2025-48700 🔴 Łataj teraz KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user…

6.1 CVSS
22.4% EPSS
synacorxss 2025-06-23
CVE-2025-66376 🔴 Łataj teraz KEV

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

7.2 CVSS
11.4% EPSS
synacorxss 2026-01-05
CVE-2012-0767 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on A…

6.1 CVSS
14.9% EPSS
adobexss 2012-02-16
CVE-2024-44309 🔴 Łataj teraz KEV
os

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing m…

6.3 CVSS
1.3% EPSS
applexss 2024-11-20
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-28741 🟠 Łataj w tym tygodniu

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

8.8 CVSS
86.4% EPSS
xss 2024-04-06
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2023-3388 🟡 Monitoruj

The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and …

7.2 CVSS
59.1% EPSS
CVE-2023-0084 🟡 Monitoruj

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and outp…

7.2 CVSS
47.8% EPSS
wpmetxss 2023-03-02
CVE-2023-1080 ⚪ Do wiadomości

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes…

6.1 CVSS
44.7% EPSS
gnpublisherxss 2023-02-28
CVE-2023-0992 🟡 Monitoruj

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject …

7.2 CVSS
38.8% EPSS
CVE-2010-0494 ⚪ Do wiadomości
appscloud

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume…

4.3 CVSS
50.2% EPSS
microsoftxss 2010-03-31
CVE-2023-0942 ⚪ Do wiadomości

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escapin…

6.1 CVSS
40.0% EPSS
artisanworkshopxss 2023-02-21
CVE-2006-3436 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack proper…

4.3 CVSS
48.6% EPSS
microsoftxss 2006-10-10
CVE-2024-2194 🟡 Monitoruj

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This…

7.2 CVSS
27.8% EPSS
xss 2024-03-13
CVE-2019-25152 🟡 Monitoruj

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.…

7.2 CVSS
27.1% EPSS
CVE-2006-5152 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an…

6.8 CVSS
27.2% EPSS
microsoftxss 2006-10-05
CVE-2024-47374 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a …

7.1 CVSS
21.0% EPSS
litespeedtechxss 2024-10-05
CVE-2022-45365 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

7.1 CVSS
20.1% EPSS
urosevicxss 2023-12-14
CVE-2020-36731 🟡 Monitoruj

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. Th…

7.2 CVSS
19.5% EPSS
wpdeskexploitxss 2023-06-07
CVE-2024-30194 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
18.7% EPSS
CVE-2024-29137 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

7.1 CVSS
16.9% EPSS
themeficxss 2024-03-19
CVE-2024-35693 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= …

7.1 CVSS
16.9% EPSS
code4recoveryxss 2024-06-08
CVE-2024-35694 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

7.1 CVSS
16.8% EPSS
amaurixss 2024-06-08
CVE-2010-0440 ⚪ Do wiadomości
network

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers…

4.3 CVSS
30.6% EPSS
ciscoexploitxss 2010-02-03
CVE-2024-29792 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor…

7.1 CVSS
14.4% EPSS
CVE-2006-5114 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command paramet…

6.8 CVSS
15.8% EPSS
sapexploitxss 2006-10-03
CVE-2026-34571 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerab…

9.9 CVSS
0.1% EPSS
CVE-2026-34569 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.9 CVSS
0.0% EPSS
CVE-2024-37261 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <…

7.1 CVSS
13.7% EPSS
wplabxss 2024-07-22
CVE-2026-1615 🟠 Łataj w tym tygodniu

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path inp…

9.8 CVSS
0.1% EPSS
rcexss 2026-02-09
CVE-2024-29931 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

7.1 CVSS
12.9% EPSS
codecabinxss 2024-03-27
CVE-2025-66562 🟠 Łataj w tym tygodniu

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Mar…

9.6 CVSS
0.2% EPSS
aiqlrcexss 2025-12-05
CVE-2026-32626 🔴 Łataj teraz

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the c…

9.6 CVSS
0.2% EPSS
CVE-2026-33976 🔴 Łataj teraz

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root caus…

9.6 CVSS
0.1% EPSS
CVE-2026-33334 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `conte…

9.6 CVSS
0.1% EPSS
vikunjarcexss 2026-03-24
CVE-2026-32890 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web da…

9.6 CVSS
0.1% EPSS
openvesslxss 2026-03-20
CVE-2026-1115 🔴 Łataj teraz

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backe…

9.6 CVSS
0.1% EPSS
lollmsexploitxss 2026-04-10
CVE-2025-69771 🟠 Łataj w tym tygodniu

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform …

9.6 CVSS
0.0% EPSS
killergerbahxss 2026-02-25
CVE-2023-5538 🟡 Monitoruj

The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This ma…

7.2 CVSS
11.2% EPSS
mrpengexploitxss 2023-10-18
CVE-2024-37259 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit …

7.1 CVSS
11.7% EPSS
wpextendedxss 2024-07-22
CVE-2006-5661 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

6.8 CVSS
13.1% EPSS
virtechexploitxss 2006-11-03
CVE-2024-29138 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Restrict User Access – Membership Plugin with Force restrict-user-access.This issue affects Restrict Us…

7.1 CVSS
11.6% EPSS
dev.institutexss 2024-03-19
CVE-2022-1707 ⚪ Do wiadomości

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization …

6.1 CVSS
16.2% EPSS
gtm4wpxss 2022-06-13
CVE-2026-27243 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27245 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27246 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScr…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-32754 🔴 Łataj teraz

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming…

9.3 CVSS
0.1% EPSS
freescoutexploitxss 2026-03-19
CVE-2026-32940 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses data:text/xml and dat…

9.3 CVSS
0.1% EPSS
b3logexploitxss 2026-03-20
CVE-2026-33135 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-33136 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaSc…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-31845 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input…

9.3 CVSS
0.0% EPSS
xss 2026-04-11
CVE-2026-30562 🟠 Łataj w tym tygodniu

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanit…

9.3 CVSS
0.0% EPSS
xss 2026-03-30
CVE-2023-0968 ⚪ Do wiadomości

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and…

6.1 CVSS
15.8% EPSS
kibokolabsxss 2023-03-03
CVE-2006-5351 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX…

9.0 CVSS
0.7% EPSS
oraclexss 2006-10-18
CVE-2025-66024 🔴 Łataj teraz

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arise…

9.0 CVSS
0.6% EPSS
CVE-2026-34558 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-34557 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-34563 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34564 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34565 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34566 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34567 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34568 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34560 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application renders user-controlled input unsaf…

9.1 CVSS
0.0% EPSS
CVE-2026-34559 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2024-43971 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
9.8% EPSS
CVE-2026-33066 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through u…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32751 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket eve…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-19
CVE-2026-39846 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption cont…

9.0 CVSS
0.1% EPSS
b3logexploitrcexss 2026-04-07
CVE-2026-33067 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject ar…

9.0 CVSS
0.1% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32635 🟠 Łataj w tym tygodniu

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulne…

9.0 CVSS
0.1% EPSS
angularxss 2026-03-16
CVE-2026-34448 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view w…

9.0 CVSS
0.1% EPSS
b3logexploitxss 2026-03-31
CVE-2026-40322 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. T…

9.0 CVSS
0.1% EPSS
b3logrcexss 2026-04-16
CVE-2026-32703 🟠 Łataj w tym tygodniu

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This a…

9.0 CVSS
0.0% EPSS
openprojectxss 2026-03-18
CVE-2026-32891 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector.…

9.0 CVSS
0.0% EPSS
openvesslxss 2026-03-20
CVE-2024-39646 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

7.1 CVSS
9.1% EPSS
kunalnagarxss 2024-08-01
CVE-2025-40892 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report contain…

8.9 CVSS
0.1% EPSS
nozominetworksxss 2025-12-18
CVE-2026-39328 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf…

8.9 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-30934 🟠 Łataj w tym tygodniu

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /publi…

8.9 CVSS
0.0% EPSS
CVE-2025-40899 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a maliciou…

8.9 CVSS
0.0% EPSS
xss 2026-04-15
CVE-2026-40487 🟡 Monitoruj

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing…

8.9 CVSS
0.0% EPSS
xss 2026-04-18
CVE-2006-5944 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.

6.8 CVSS
10.4% EPSS
CVE-2022-2541 🟡 Monitoruj

The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/act…

8.8 CVSS
0.3% EPSS
CVE-2022-2542 🟡 Monitoruj

The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/…

8.8 CVSS
0.3% EPSS
CVE-2026-3533 🟡 Monitoruj

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function …

8.8 CVSS
0.3% EPSS
rcexss 2026-03-24
CVE-2026-33336 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not…

8.8 CVSS
0.3% EPSS
CVE-2022-2540 🟡 Monitoruj

The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function …

8.8 CVSS
0.2% EPSS
CVE-2025-57151 🟠 Łataj w tym tygodniu

phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.

8.8 CVSS
0.1% EPSS
CVE-2006-5975 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

6.8 CVSS
10.1% EPSS
drumsterexploitxss 2006-11-20
CVE-2026-33506 🟠 Łataj w tym tygodniu

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis's login…

8.8 CVSS
0.1% EPSS
oryexploitxss 2026-03-26
CVE-2026-33510 🟠 Łataj w tym tygodniu

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl),…

8.8 CVSS
0.1% EPSS
homarrexploitxss 2026-04-06
CVE-2026-33124 🟡 Monitoruj

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current passwo…

8.8 CVSS
0.0% EPSS
frigatexss 2026-03-20
CVE-2024-2834 🟡 Monitoruj

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

8.7 CVSS
0.1% EPSS
xss 2024-04-08
CVE-2026-33348 🟠 Łataj w tym tygodniu

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form …

8.7 CVSS
0.1% EPSS
open-emrexploitxss 2026-03-25
CVE-2026-33346 🟠 Łataj w tym tygodniu

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a pat…

8.7 CVSS
0.0% EPSS
open-emrexploitxss 2026-03-19
CVE-2026-30587 🟠 Łataj w tym tygodniu

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properl…

8.7 CVSS
0.0% EPSS
seafileexploitxss 2026-03-25
CVE-2026-34748 🟡 Monitoruj

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with …

8.7 CVSS
0.0% EPSS
payloadcmsxss 2026-04-01
CVE-2026-34617 🟡 Monitoruj

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject …

8.7 CVSS
0.0% EPSS
CVE-2026-32277 🟡 Monitoruj

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 con…

8.7 CVSS
0.0% EPSS
CVE-2025-10553 🟡 Monitoruj

A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execut…

8.7 CVSS
0.0% EPSS
3dsxss 2026-03-31
CVE-2026-35576 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-39332 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of a…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-39333 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding fo…

8.7 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-35169 🟡 Monitoruj

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of …

8.7 CVSS
0.0% EPSS
mcgillxss 2026-04-08
CVE-2025-10551 🟡 Monitoruj

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execut…

8.7 CVSS
0.0% EPSS
3dsxss 2026-03-31
CVE-2026-35569 🟠 Łataj w tym tygodniu

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controll…

8.7 CVSS
0.0% EPSS
CVE-2026-33172 🟡 Monitoruj

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to by…

8.7 CVSS
0.0% EPSS
statamicxss 2026-03-20
CVE-2025-4123 🟡 Monitoruj

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will exec…

7.6 CVSS
5.3% EPSS
CVE-2023-6600 🟡 Monitoruj

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings…

8.6 CVSS
0.2% EPSS
daanxss 2024-01-03
CVE-2026-34585 🟠 Łataj w tym tygodniu

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special chara…

8.6 CVSS
0.1% EPSS
b3logexploitrcexss 2026-03-31
CVE-2026-33955 🟠 Łataj w tym tygodniu

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. Th…

8.6 CVSS
0.1% EPSS
CVE-2026-32721 🟡 Monitoruj

LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without…

8.6 CVSS
0.0% EPSS
openwrtxss 2026-03-19
CVE-2024-28734 ⚪ Do wiadomości

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

6.1 CVSS
11.3% EPSS
xss 2024-03-19
CVE-2024-22397 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScrip…

8.3 CVSS
0.2% EPSS
xss 2024-03-14
CVE-2006-5524 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

6.8 CVSS
7.7% EPSS
phplistexploitxss 2006-10-26
CVE-2026-34780 🟡 Monitoruj

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-…

8.3 CVSS
0.0% EPSS
electronjsxss 2026-04-04
CVE-2024-2050 🟡 Monitoruj

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the prod…

8.2 CVSS
0.1% EPSS
xss 2024-03-18
CVE-2019-25676 🟠 Łataj w tym tygodniu

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags throu…

8.2 CVSS
0.1% EPSS
CVE-2026-32278 🟡 Monitoruj

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file…

8.2 CVSS
0.0% EPSS
CVE-2026-2072 🟡 Monitoruj

Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Ana…

8.2 CVSS
0.0% EPSS
xss 2026-03-25
CVE-2026-34375 🟠 Łataj w tym tygodniu

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any e…

8.2 CVSS
0.0% EPSS
wwbnexploitxss 2026-03-27
CVE-2026-34725 🟡 Monitoruj

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitizatio…

8.2 CVSS
0.0% EPSS
xss 2026-04-02
CVE-2026-33331 🟠 Łataj w tym tygodniu

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scripting (XSS) vulnerability exists in the OpenAPI documentation generati…

8.2 CVSS
0.0% EPSS
orpcexploitxss 2026-03-24
CVE-2026-33979 🟠 Łataj w tym tygodniu

Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identifi…

8.2 CVSS
0.0% EPSS
CVE-2024-24336 🟡 Monitoruj

A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff user…

8.1 CVSS
0.2% EPSS
xss 2024-03-19
CVE-2025-64759 🟡 Monitoruj

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the r…

8.1 CVSS
0.1% EPSS
homarrxss 2025-11-19
CVE-2025-49552 🟡 Monitoruj

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Explo…

8.1 CVSS
0.1% EPSS
adobexss 2025-10-14
CVE-2006-5164 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.

6.8 CVSS
6.5% EPSS
CVE-2006-5915 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type…

6.8 CVSS
6.5% EPSS
samediaexploitxss 2006-11-15
CVE-2026-39344 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the userna…

8.1 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-27196 🟡 Monitoruj

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated u…

8.1 CVSS
0.0% EPSS
statamicxss 2026-02-21
CVE-2026-40497 🟡 Monitoruj

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. T…

8.1 CVSS
0.0% EPSS
CVE-2006-5853 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web script or HTML via the lang parameter, which is returned to the client in a…

6.8 CVSS
6.4% EPSS
immediacyexploitxss 2006-11-10
CVE-2026-35575 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to…

8.0 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2006-6022 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

6.8 CVSS
5.2% EPSS
CVE-2022-45836 ⚪ Do wiadomości

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

6.3 CVSS
7.2% EPSS
w3edenxss 2023-04-18
CVE-2023-0038 🟡 Monitoruj

The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and ou…

7.2 CVSS
2.5% EPSS
ays-proexploitxss 2023-01-03
CVE-2006-5958 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) searc…

6.8 CVSS
4.2% EPSS
CVE-2026-32308 🟡 Monitoruj

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This con…

7.6 CVSS
0.0% EPSS
hackerbayexploitxss 2026-03-13
CVE-2026-33673 🟡 Monitoruj

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the da…

7.6 CVSS
0.0% EPSS
xss 2026-03-26
CVE-2024-42210 🟡 Monitoruj

A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives …

7.6 CVSS
0.0% EPSS
hcltechxss 2026-03-19
CVE-2026-24750 🟡 Monitoruj

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation as Stored XSS when …

7.6 CVSS
0.0% EPSS
accellionxss 2026-03-25
CVE-2026-33932 🟡 Monitoruj

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attack…

7.6 CVSS
0.0% EPSS
open-emrxss 2026-03-26
CVE-2026-34529 🟡 Monitoruj

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to…

7.6 CVSS
0.0% EPSS
CVE-2026-35534 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute …

7.6 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2022-0889 🟡 Monitoruj

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php f…

7.2 CVSS
2.0% EPSS
ninjaformsxss 2022-03-23
CVE-2026-5301 🟡 Monitoruj

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries

7.6 CVSS
0.0% EPSS
xss 2026-04-08
CVE-2026-32728 🟡 Monitoruj

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter …

7.6 CVSS
0.0% EPSS
parseplatformxss 2026-03-18
CVE-2023-3092 🟡 Monitoruj

The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping when the 'Save Data…

7.2 CVSS
1.9% EPSS
photoboxonexss 2023-07-12
CVE-2023-1372 🟡 Monitoruj

The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficie…

7.2 CVSS
1.8% EPSS
CVE-2022-4712 🟡 Monitoruj

The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated…

7.2 CVSS
1.8% EPSS
cerberxss 2023-10-20
CVE-2022-4027 🟡 Monitoruj

The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitiza…

7.2 CVSS
1.8% EPSS
simple-pressxss 2022-11-29
CVE-2024-1226 🟡 Monitoruj

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the f…

7.5 CVSS
0.1% EPSS
xss 2024-03-12
CVE-2013-20006 🟡 Monitoruj

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users. Attackers can injec…

7.5 CVSS
0.1% EPSS
xss 2026-03-16
CVE-2026-26027 🟡 Monitoruj

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

7.5 CVSS
0.0% EPSS
glpi-projectxss 2026-04-06
CVE-2026-40286 🟡 Monitoruj

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) function. By injecting a pa…

7.5 CVSS
0.0% EPSS
xss 2026-04-17
CVE-2023-4719 🟡 Monitoruj

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping.…

7.2 CVSS
1.4% EPSS
CVE-2023-1912 🟡 Monitoruj

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. …

7.2 CVSS
1.4% EPSS
CVE-2023-47505 ⚪ Do wiadomości

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.

6.5 CVSS
4.8% EPSS
elementorexploitxss 2023-11-30
CVE-2024-1774 🟡 Monitoruj

The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in all versions up to, and including, 1.23.3 due to insufficient input sanitization and output escapin…

7.2 CVSS
1.3% EPSS
xss 2024-04-09
CVE-2023-2298 🟡 Monitoruj

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficien…

7.2 CVSS
1.2% EPSS
vcitaxss 2023-06-03
CVE-2006-5499 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in Serendipity (s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the media manager administration page.

6.8 CVSS
3.2% EPSS
serendipityxss 2006-10-25
CVE-2019-25146 🟡 Monitoruj

The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that had no capability checks in versions up to, and including, 2.1.7 due to insufficient input sanitizati…

7.2 CVSS
1.2% EPSS
delucksexploitxss 2023-06-07
CVE-2023-6811 🟡 Monitoruj

The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input s…

7.2 CVSS
1.2% EPSS
xss 2024-04-11
CVE-2006-5108 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php…

6.8 CVSS
3.2% EPSS
devellionexploitxss 2006-10-03
CVE-2023-3158 🟡 Monitoruj

The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it po…

7.2 CVSS
1.1% EPSS
instarezaxss 2023-07-12
CVE-2019-25147 🟡 Monitoruj

The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and o…

7.2 CVSS
1.1% EPSS
CVE-2021-4358 🟡 Monitoruj

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. Th…

7.2 CVSS
1.1% EPSS
legalwebexploitxss 2023-06-07
CVE-2020-36769 🟡 Monitoruj

The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient…

7.4 CVSS
0.1% EPSS
CVE-2024-2459 🟡 Monitoruj

The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on us…

7.4 CVSS
0.1% EPSS
xss 2024-03-20
CVE-2021-4365 🟡 Monitoruj

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on…

7.2 CVSS
1.1% EPSS
CVE-2023-2757 🟡 Monitoruj

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Sit…

7.4 CVSS
0.0% EPSS
pluginxss 2023-05-18
CVE-2023-3080 🟡 Monitoruj

The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it…

7.2 CVSS
0.9% EPSS
jameswardxss 2023-07-12
CVE-2023-3082 🟡 Monitoruj

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possibl…

7.2 CVSS
0.9% EPSS
wpexpertsxss 2023-07-12
CVE-2023-3088 🟡 Monitoruj

The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possi…

7.2 CVSS
0.9% EPSS
wpvibesxss 2023-07-12
CVE-2023-3093 🟡 Monitoruj

The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible …

7.2 CVSS
0.9% EPSS
yaycommercexss 2023-07-12
CVE-2023-3122 🟡 Monitoruj

The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it pos…

7.2 CVSS
0.9% EPSS
dev4pressxss 2023-07-12
CVE-2023-3135 🟡 Monitoruj

The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes …

7.2 CVSS
0.9% EPSS
oacstudioxss 2023-07-12
CVE-2023-3166 🟡 Monitoruj

The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping.…

7.2 CVSS
0.9% EPSS
lanacodesxss 2023-07-12
CVE-2023-3168 🟡 Monitoruj

The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes i…

7.2 CVSS
0.9% EPSS
CVE-2023-3081 🟡 Monitoruj

The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it …

7.2 CVSS
0.8% EPSS
awesomemotivexss 2023-07-12
CVE-2023-3087 🟡 Monitoruj

The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it poss…

7.2 CVSS
0.8% EPSS
wpmanageninjaxss 2023-07-12
CVE-2019-25140 🟡 Monitoruj

The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logo_width, logo_height, rcsp_logo_url, home_sec_link_txt, rcsp_headline and rcsp_description pa…

7.2 CVSS
0.8% EPSS
CVE-2023-7027 🟡 Monitoruj

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and inclu…

7.2 CVSS
0.8% EPSS
wpexpertsexploitxss 2024-01-03
CVE-2024-32568 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2FA: from n/a through <= 2.6.2.

7.1 CVSS
1.2% EPSS
melapressxss 2024-04-18
CVE-2023-3136 🟡 Monitoruj

The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it p…

7.2 CVSS
0.6% EPSS
perfopsonexss 2023-08-30
CVE-2026-24045 🟡 Monitoruj

Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into met…

7.3 CVSS
0.0% EPSS
docmostexploitxss 2026-02-10
CVE-2026-35574 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authenticated users with note-adding permissions to execute arbitr…

7.3 CVSS
0.0% EPSS
CVE-2026-33080 🟡 Monitoruj

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database val…

7.3 CVSS
0.0% EPSS
filamentphpxss 2026-03-20
CVE-2026-28754 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-28756 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-28703 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-3879 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-3880 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-4107 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03
CVE-2026-4108 🟡 Monitoruj

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

7.3 CVSS
0.0% EPSS
zohocorpxss 2026-04-03