CVE z tagiem xss — 200 wyników. ← Wszystkie tagi

CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2020-3580 🔴 Łataj teraz KEV
network

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cros…

6.1 CVSS
85.6% EPSS
ciscoxss 2020-10-21
CVE-2014-2120 🔴 Łataj teraz KEV
network

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug I…

6.1 CVSS
69.8% EPSS
ciscoxss 2014-03-19
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2018-19943 🔴 Łataj teraz KEV

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS …

8.0 CVSS
17.7% EPSS
qnapxss 2020-10-28
CVE-2018-6882 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary …

6.1 CVSS
25.4% EPSS
synacorexploitxss 2018-03-27
CVE-2018-19953 🔴 Łataj teraz KEV

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.120…

6.1 CVSS
23.9% EPSS
qnapxss 2020-10-28
CVE-2025-48700 🔴 Łataj teraz KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user…

6.1 CVSS
22.4% EPSS
synacorxss 2025-06-23
CVE-2025-66376 🔴 Łataj teraz KEV

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

7.2 CVSS
11.4% EPSS
synacorxss 2026-01-05
CVE-2012-0767 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on A…

6.1 CVSS
14.9% EPSS
adobexss 2012-02-16
CVE-2026-42897 🔴 Łataj teraz KEV
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

8.1 CVSS
2.5% EPSS
microsoftxss 2026-05-14
CVE-2024-44309 🔴 Łataj teraz KEV
os

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing m…

6.3 CVSS
1.3% EPSS
applexss 2024-11-20
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-28741 🟠 Łataj w tym tygodniu

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

8.8 CVSS
86.4% EPSS
xss 2024-04-06
CVE-2021-25299 ⚪ Do wiadomości

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously c…

6.1 CVSS
97.7% EPSS
nagiosexploitrcexss 2021-02-15
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2021-36450 ⚪ Do wiadomości

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

6.1 CVSS
64.9% EPSS
verintexploitxss 2021-12-15
CVE-2023-3388 🟡 Monitoruj

The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and …

7.2 CVSS
59.1% EPSS
CVE-2023-41425 ⚪ Do wiadomości

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

6.1 CVSS
54.3% EPSS
wondercmsexploitxss 2023-11-07
CVE-2023-0084 🟡 Monitoruj

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and outp…

7.2 CVSS
47.8% EPSS
wpmetxss 2023-03-02
CVE-2022-33098 ⚪ Do wiadomości

Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG docu…

6.1 CVSS
51.6% EPSS
magnolia-cmsxss 2022-07-07
CVE-2021-30119 ⚪ Do wiadomości

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Examp…

5.4 CVSS
52.7% EPSS
kaseyaexploitxss 2021-07-09
CVE-2023-1080 ⚪ Do wiadomości

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes…

6.1 CVSS
44.7% EPSS
gnpublisherxss 2023-02-28
CVE-2023-0992 🟡 Monitoruj

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject …

7.2 CVSS
38.8% EPSS
CVE-2016-7981 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

6.1 CVSS
43.5% EPSS
spipxss 2017-01-18
CVE-2022-26263 ⚪ Do wiadomości

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

6.1 CVSS
41.4% EPSS
yonyouexploitxss 2022-03-25
CVE-2010-0494 ⚪ Do wiadomości
appscloud

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume…

4.3 CVSS
50.2% EPSS
microsoftxss 2010-03-31
CVE-2023-0942 ⚪ Do wiadomości

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escapin…

6.1 CVSS
40.0% EPSS
artisanworkshopxss 2023-02-21
CVE-2006-3436 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack proper…

4.3 CVSS
48.6% EPSS
microsoftxss 2006-10-10
CVE-2022-36533 ⚪ Do wiadomości
os

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

5.4 CVSS
41.6% EPSS
linuxexploitxss 2022-09-16
CVE-2024-2194 🟡 Monitoruj

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This…

7.2 CVSS
27.8% EPSS
xss 2024-03-13
CVE-2019-25152 🟡 Monitoruj

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.…

7.2 CVSS
27.1% EPSS
CVE-2006-5152 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an…

6.8 CVSS
27.2% EPSS
microsoftxss 2006-10-05
CVE-2024-47374 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a …

7.1 CVSS
21.0% EPSS
litespeedtechxss 2024-10-05
CVE-2022-45365 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

7.1 CVSS
20.1% EPSS
urosevicxss 2023-12-14
CVE-2020-36731 🟡 Monitoruj

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. Th…

7.2 CVSS
19.5% EPSS
wpdeskexploitxss 2023-06-07
CVE-2024-30194 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
18.7% EPSS
CVE-2024-57041 ⚪ Do wiadomości

A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.

4.6 CVSS
30.5% EPSS
nodebbexploitxss 2025-01-24
CVE-2024-29137 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

7.1 CVSS
16.9% EPSS
themeficxss 2024-03-19
CVE-2024-35693 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= …

7.1 CVSS
16.9% EPSS
code4recoveryxss 2024-06-08
CVE-2024-35694 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

7.1 CVSS
16.8% EPSS
amaurixss 2024-06-08
CVE-2010-0440 ⚪ Do wiadomości
network

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers…

4.3 CVSS
30.6% EPSS
ciscoexploitxss 2010-02-03
CVE-2024-42467 🟠 Łataj w tym tygodniu

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed…

10.0 CVSS
1.0% EPSS
openhabrcessrfxss 2024-08-12
CVE-2026-1615 🟠 Łataj w tym tygodniu

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path inp…

9.8 CVSS
1.1% EPSS
rcexss 2026-02-09
CVE-2026-45087 🟠 Łataj w tym tygodniu

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no…

10.0 CVSS
0.1% EPSS
xss 2026-05-27
CVE-2026-50551 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remo…

9.9 CVSS
0.4% EPSS
rcexss 2026-06-24
CVE-2024-29792 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor…

7.1 CVSS
14.4% EPSS
CVE-2006-5114 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command paramet…

6.8 CVSS
15.8% EPSS
sapexploitxss 2006-10-03
CVE-2026-54067 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via insertAdjacentHTML. A…

9.9 CVSS
0.3% EPSS
rcexss 2026-06-24
CVE-2026-54158 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsse…

9.9 CVSS
0.3% EPSS
rcexss 2026-06-24
CVE-2026-34571 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerab…

9.9 CVSS
0.1% EPSS
CVE-2026-34569 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.9 CVSS
0.0% EPSS
CVE-2026-25200 🟠 Łataj w tym tygodniu

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.…

9.8 CVSS
0.5% EPSS
samsungxss 2026-02-02
CVE-2025-52161 🟠 Łataj w tym tygodniu

Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.

9.8 CVSS
0.4% EPSS
schollxss 2025-09-08
CVE-2026-53787 🟠 Łataj w tym tygodniu

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by …

9.8 CVSS
0.2% EPSS
CVE-2024-37261 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <…

7.1 CVSS
13.7% EPSS
wplabxss 2024-07-22
CVE-2023-38888 🔴 Łataj teraz

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScrip…

9.6 CVSS
1.1% EPSS
dolibarrexploitxss 2023-09-20
CVE-2025-14320 🟠 Łataj w tym tygodniu

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS. Th…

9.8 CVSS
0.1% EPSS
xss 2026-05-04
CVE-2024-3166 🔴 Łataj teraz

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the appli…

9.6 CVSS
1.0% EPSS
CVE-2022-36180 🔴 Łataj teraz

Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout…

9.6 CVSS
0.9% EPSS
CVE-2024-44779 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted p…

9.6 CVSS
0.7% EPSS
vtigerxss 2024-08-29
CVE-2026-55008 🟠 Łataj w tym tygodniu

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

9.6 CVSS
0.7% EPSS
xss 2026-07-14
CVE-2024-44778 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted pay…

9.6 CVSS
0.7% EPSS
vtigerxss 2024-08-29
CVE-2024-44777 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payloa…

9.6 CVSS
0.7% EPSS
vtigerxss 2024-08-29
CVE-2022-37830 🔴 Łataj teraz

Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).

9.6 CVSS
0.7% EPSS
webjetexploitxss 2023-10-19
CVE-2023-45992 🔴 Łataj teraz

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user …

9.6 CVSS
0.6% EPSS
commscopeexploitxss 2023-10-19
CVE-2026-27148 🟠 Łataj w tym tygodniu

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create…

9.6 CVSS
0.5% EPSS
storybookrcexss 2026-02-25
CVE-2015-6477 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors…

6.1 CVSS
18.0% EPSS
nordexxss 2015-10-18
CVE-2026-70332 🟠 Łataj w tym tygodniu
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

9.6 CVSS
0.5% EPSS
microsoftxss 2026-08-07
CVE-2026-56395 🟠 Łataj w tym tygodniu

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code executio…

9.6 CVSS
0.4% EPSS
rcexss 2026-06-21
CVE-2026-56397 🟠 Łataj w tym tygodniu

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code executio…

9.6 CVSS
0.4% EPSS
rcexss 2026-06-21
CVE-2024-29931 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

7.1 CVSS
12.9% EPSS
codecabinxss 2024-03-27
CVE-2026-55085 🟠 Łataj w tym tygodniu

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assignin…

9.6 CVSS
0.4% EPSS
xss 2026-08-19
CVE-2026-54458 🟠 Łataj w tym tygodniu

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript i…

9.6 CVSS
0.3% EPSS
xss 2026-07-15
CVE-2026-57625 🟠 Łataj w tym tygodniu

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.

9.6 CVSS
0.3% EPSS
xss 2026-07-02
CVE-2025-66562 🟠 Łataj w tym tygodniu

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Mar…

9.6 CVSS
0.2% EPSS
aiqlrcexss 2025-12-05
CVE-2026-53662 🟠 Łataj w tym tygodniu

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully c…

9.6 CVSS
0.2% EPSS
xss 2026-06-23
CVE-2026-42090 🟠 Łataj w tym tygodniu

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow ca…

9.6 CVSS
0.2% EPSS
streetwritersrcexss 2026-05-04
CVE-2026-32626 🔴 Łataj teraz

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the c…

9.6 CVSS
0.2% EPSS
CVE-2026-33976 🔴 Łataj teraz

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root caus…

9.6 CVSS
0.1% EPSS
CVE-2026-33334 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `conte…

9.6 CVSS
0.1% EPSS
vikunjarcexss 2026-03-24
CVE-2026-32890 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web da…

9.6 CVSS
0.1% EPSS
openvesslxss 2026-03-20
CVE-2026-1115 🔴 Łataj teraz

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backe…

9.6 CVSS
0.1% EPSS
lollmsexploitxss 2026-04-10
CVE-2025-69771 🟠 Łataj w tym tygodniu

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform …

9.6 CVSS
0.0% EPSS
killergerbahxss 2026-02-25
CVE-2026-48320 🟡 Monitoruj

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control ove…

8.5 CVSS
5.3% EPSS
adobexss 2026-07-14
CVE-2023-5538 🟡 Monitoruj

The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This ma…

7.2 CVSS
11.2% EPSS
mrpengexploitxss 2023-10-18
CVE-2024-37259 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit …

7.1 CVSS
11.7% EPSS
wpextendedxss 2024-07-22
CVE-2026-70306 🟠 Łataj w tym tygodniu
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

9.3 CVSS
0.6% EPSS
microsoftxss 2026-08-11
CVE-2006-5661 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

6.8 CVSS
13.1% EPSS
virtechexploitxss 2006-11-03
CVE-2024-29138 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Restrict User Access – Membership Plugin with Force restrict-user-access.This issue affects Restrict Us…

7.1 CVSS
11.6% EPSS
dev.institutexss 2024-03-19
CVE-2025-8668 🟠 Łataj w tym tygodniu

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows…

9.4 CVSS
0.0% EPSS
xss 2026-02-11
CVE-2026-44990 🟠 Łataj w tym tygodniu

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can tur…

9.3 CVSS
0.5% EPSS
xss 2026-06-12
CVE-2026-25896 🔴 Łataj teraz

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as…

9.3 CVSS
0.5% EPSS
CVE-2026-31845 🟠 Łataj w tym tygodniu

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input…

9.3 CVSS
0.4% EPSS
xss 2026-04-11
CVE-2026-39878 🟠 Łataj w tym tygodniu

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's br…

9.3 CVSS
0.4% EPSS
xss 2026-07-20
CVE-2026-2342 🟠 Łataj w tym tygodniu

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: T…

9.3 CVSS
0.4% EPSS
xss 2026-07-09
CVE-2026-34691 🟠 Łataj w tym tygodniu

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …

9.3 CVSS
0.4% EPSS
adobexss 2026-06-09
CVE-2026-66421 🟠 Łataj w tym tygodniu

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into ag…

9.3 CVSS
0.4% EPSS
xss 2026-07-30
CVE-2026-66418 🟠 Łataj w tym tygodniu

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login …

9.3 CVSS
0.3% EPSS
xss 2026-07-30
CVE-2026-12048 🟠 Łataj w tym tygodniu

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist er…

9.3 CVSS
0.3% EPSS
pgadminxss 2026-06-19
CVE-2026-34932 🟠 Łataj w tym tygodniu

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.

9.3 CVSS
0.3% EPSS
hoppscotchxss 2026-04-02
CVE-2026-48768 🟠 Łataj w tym tygodniu

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issu…

9.3 CVSS
0.3% EPSS
xss 2026-06-18
CVE-2026-47646 🟠 Łataj w tym tygodniu
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

9.3 CVSS
0.3% EPSS
microsoftxss 2026-07-09
CVE-2026-9264 🟠 Łataj w tym tygodniu

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improp…

9.3 CVSS
0.2% EPSS
rcexss 2026-05-22
CVE-2026-11708 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.

9.3 CVSS
0.2% EPSS
ibmxss 2026-06-30
CVE-2026-11712 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

9.3 CVSS
0.2% EPSS
ibmxss 2026-06-30
CVE-2026-11707 🟠 Łataj w tym tygodniu

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

9.3 CVSS
0.2% EPSS
ibmxss 2026-07-30
CVE-2022-1707 ⚪ Do wiadomości

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization …

6.1 CVSS
16.2% EPSS
gtm4wpxss 2022-06-13
CVE-2026-27243 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27245 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-27246 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScr…

9.3 CVSS
0.1% EPSS
adobexss 2026-04-14
CVE-2026-32754 🔴 Łataj teraz

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming…

9.3 CVSS
0.1% EPSS
freescoutexploitxss 2026-03-19
CVE-2026-32940 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses data:text/xml and dat…

9.3 CVSS
0.1% EPSS
b3logexploitxss 2026-03-20
CVE-2026-44212 🟠 Łataj w tym tygodniu

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attack…

9.3 CVSS
0.1% EPSS
xss 2026-05-14
CVE-2026-33135 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-33136 🔴 Łataj teraz

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaSc…

9.3 CVSS
0.0% EPSS
wegiaexploitxss 2026-03-20
CVE-2026-42849 🟠 Łataj w tym tygodniu

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy br…

9.3 CVSS
0.0% EPSS
goauthentikxss 2026-06-02
CVE-2026-30562 🟠 Łataj w tym tygodniu

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanit…

9.3 CVSS
0.0% EPSS
xss 2026-03-30
CVE-2026-43900 🟠 Łataj w tym tygodniu

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend…

9.3 CVSS
0.0% EPSS
xss 2026-05-11
CVE-2023-0968 ⚪ Do wiadomości

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and…

6.1 CVSS
15.8% EPSS
kibokolabsxss 2023-03-03
CVE-2022-31358 🔴 Łataj teraz

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

9.0 CVSS
1.3% EPSS
proxmoxexploitxss 2022-12-14
CVE-2022-42989 🔴 Łataj teraz

ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

9.0 CVSS
0.8% EPSS
sankhyaexploitxss 2022-11-22
CVE-2022-37720 🔴 Łataj teraz

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admi…

9.0 CVSS
0.8% EPSS
CVE-2006-5351 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX…

9.0 CVSS
0.7% EPSS
oraclexss 2006-10-18
CVE-2022-37721 🟠 Łataj w tym tygodniu

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privi…

9.0 CVSS
0.7% EPSS
CVE-2022-32114 🟠 Łataj w tym tygodniu

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Medi…

8.8 CVSS
1.6% EPSS
strapiexploitxss 2022-07-13
CVE-2026-34558 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-34557 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.1% EPSS
CVE-2026-39846 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption cont…

9.0 CVSS
0.5% EPSS
b3logexploitrcexss 2026-04-07
CVE-2026-34563 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34564 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34565 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34566 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34567 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34568 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-41201 🟠 Łataj w tym tygodniu

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege…

9.1 CVSS
0.0% EPSS
CVE-2026-34560 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application renders user-controlled input unsaf…

9.1 CVSS
0.0% EPSS
CVE-2026-34559 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con…

9.1 CVSS
0.0% EPSS
CVE-2026-34448 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view w…

9.0 CVSS
0.5% EPSS
b3logexploitxss 2026-03-31
CVE-2026-35198 🟠 Łataj w tym tygodniu

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes …

9.0 CVSS
0.5% EPSS
CVE-2025-34157 🟠 Łataj w tym tygodniu

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously…

9.0 CVSS
0.4% EPSS
coollabsxss 2025-08-27
CVE-2026-24769 🔴 Łataj teraz

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload mali…

9.0 CVSS
0.4% EPSS
nocodbexploitxss 2026-01-28
CVE-2025-66024 🔴 Łataj teraz

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. …

9.0 CVSS
0.4% EPSS
CVE-2026-55570 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of eac…

9.0 CVSS
0.3% EPSS
xss 2026-06-24
CVE-2026-62378 🟠 Łataj w tym tygodniu

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF …

9.0 CVSS
0.3% EPSS
xss 2026-07-15
CVE-2024-43971 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= …

7.1 CVSS
9.8% EPSS
CVE-2025-34175 ⚪ Do wiadomości

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scri…

6.1 CVSS
14.8% EPSS
pfsensexss 2025-09-09
CVE-2026-33066 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through u…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32751 🔴 Łataj teraz

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket eve…

9.0 CVSS
0.2% EPSS
b3logexploitrcexss 2026-03-19
CVE-2026-33067 🔴 Łataj teraz

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject ar…

9.0 CVSS
0.1% EPSS
b3logexploitrcexss 2026-03-20
CVE-2026-32635 🟠 Łataj w tym tygodniu

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulne…

9.0 CVSS
0.1% EPSS
angularxss 2026-03-16
CVE-2026-40322 🟠 Łataj w tym tygodniu

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. T…

9.0 CVSS
0.1% EPSS
b3logrcexss 2026-04-16
CVE-2026-42457 🟠 Łataj w tym tygodniu

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name …

9.0 CVSS
0.1% EPSS
xss 2026-05-14
CVE-2026-42523 🟠 Łataj w tym tygodniu
dev

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site sc…

9.0 CVSS
0.0% EPSS
jenkinsxss 2026-04-29
CVE-2026-36748 🟠 Łataj w tym tygodniu

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

9.0 CVSS
0.0% EPSS
xss 2026-06-03
CVE-2026-32703 🟠 Łataj w tym tygodniu

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This a…

9.0 CVSS
0.0% EPSS
openprojectxss 2026-03-18
CVE-2026-32891 🟠 Łataj w tym tygodniu

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector.…

9.0 CVSS
0.0% EPSS
openvesslxss 2026-03-20
CVE-2026-52798 🟡 Monitoruj

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitiz…

8.9 CVSS
0.4% EPSS
xss 2026-06-24
CVE-2026-57858 🟡 Monitoruj

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a…

8.9 CVSS
0.4% EPSS
xss 2026-08-12
CVE-2026-57104 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

8.8 CVSS
0.8% EPSS
xss 2026-08-11
CVE-2024-58353 🟡 Monitoruj

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendere…

8.9 CVSS
0.3% EPSS
xss 2026-07-23
CVE-2024-58355 🟡 Monitoruj

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dan…

8.9 CVSS
0.3% EPSS
xss 2026-07-23
CVE-2026-7569 🟡 Monitoruj

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2026-9780 🟡 Monitoruj

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2024-39646 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

7.1 CVSS
9.1% EPSS
kunalnagarxss 2024-08-01
CVE-2025-40892 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report contain…

8.9 CVSS
0.1% EPSS
nozominetworksxss 2025-12-18
CVE-2026-39328 🟡 Monitoruj

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf…

8.9 CVSS
0.0% EPSS
churchcrmxss 2026-04-07
CVE-2026-38949 🟡 Monitoruj

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing inject…

8.9 CVSS
0.0% EPSS
xss 2026-04-28
CVE-2025-11956 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS. This issue affects OBS (S…

8.9 CVSS
0.0% EPSS
xss 2025-11-06
CVE-2025-10467 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Stored…

8.9 CVSS
0.0% EPSS
xss 2025-09-25
CVE-2025-9798 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS. This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

8.9 CVSS
0.0% EPSS
xss 2025-09-23
CVE-2026-43984 🟡 Monitoruj

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint w…

8.9 CVSS
0.0% EPSS
xss 2026-06-04
CVE-2026-48307 🟡 Monitoruj

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially …

8.8 CVSS
0.5% EPSS
adobercexss 2026-06-30
CVE-2026-30934 🟠 Łataj w tym tygodniu

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /publi…

8.9 CVSS
0.0% EPSS
CVE-2025-40899 🟡 Monitoruj

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a maliciou…

8.9 CVSS
0.0% EPSS
xss 2026-04-15
CVE-2026-40487 🟡 Monitoruj

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing…

8.9 CVSS
0.0% EPSS
xss 2026-04-18
CVE-2026-42611 🟡 Monitoruj

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire sys…

8.9 CVSS
0.0% EPSS
rcexss 2026-05-11
CVE-2026-65767 🟡 Monitoruj
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

8.8 CVSS
0.4% EPSS
microsoftxss 2026-08-11
CVE-2006-5944 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.

6.8 CVSS
10.4% EPSS
CVE-2025-51629 🟡 Monitoruj

A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.

8.8 CVSS
0.3% EPSS
xss 2025-08-07
CVE-2022-2541 🟡 Monitoruj

The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/act…

8.8 CVSS
0.3% EPSS
CVE-2022-2542 🟡 Monitoruj

The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/…

8.8 CVSS
0.3% EPSS
CVE-2026-61875 🟡 Monitoruj

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortM…

8.8 CVSS
0.3% EPSS
xss 2026-07-12
CVE-2026-71386 🟡 Monitoruj

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vuln…

8.8 CVSS
0.3% EPSS
adobercexss 2026-08-11
CVE-2026-3533 🟡 Monitoruj

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function …

8.8 CVSS
0.3% EPSS
rcexss 2026-03-24
CVE-2026-32208 🟡 Monitoruj
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

8.8 CVSS
0.3% EPSS
microsoftxss 2026-06-19
CVE-2026-11589 🟡 Monitoruj

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) …

8.8 CVSS
0.3% EPSS
xss 2026-06-30
CVE-2026-33336 🟠 Łataj w tym tygodniu

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not…

8.8 CVSS
0.3% EPSS
CVE-2026-13609 🟡 Monitoruj

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded pay…

8.8 CVSS
0.2% EPSS
xss 2026-07-31
CVE-2022-2540 🟡 Monitoruj

The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function …

8.8 CVSS
0.2% EPSS
CVE-2025-57151 🟠 Łataj w tym tygodniu

phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.

8.8 CVSS
0.1% EPSS
CVE-2026-1819 🟡 Monitoruj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 2301202…

8.8 CVSS
0.1% EPSS
xss 2026-02-04
CVE-2006-5975 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

6.8 CVSS
10.1% EPSS
drumsterexploitxss 2006-11-20
CVE-2026-33506 🟠 Łataj w tym tygodniu

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis's login…

8.8 CVSS
0.1% EPSS
oryexploitxss 2026-03-26
CVE-2026-33510 🟠 Łataj w tym tygodniu

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl),…

8.8 CVSS
0.1% EPSS
homarrexploitxss 2026-04-06
CVE-2026-32207 🟡 Monitoruj
appscloud

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

8.8 CVSS
0.1% EPSS
microsoftxss 2026-05-07
CVE-2026-33124 🟡 Monitoruj

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current passwo…

8.8 CVSS
0.0% EPSS
frigatexss 2026-03-20
CVE-2026-3220 🟡 Monitoruj

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a pr…

8.8 CVSS
0.0% EPSS
xss 2026-05-18
CVE-2026-7498 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue aff…

8.8 CVSS
0.0% EPSS
xss 2026-05-18
CVE-2026-3953 🟡 Monitoruj

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. T…

8.8 CVSS
0.0% EPSS
xss 2026-05-07