VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

1676 CVEsRSS

CVE-2026-94488High· 8.2
today

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. How…

TwilightTelegram · Telegram Desktopvia CVEORG
CVE-2026-58504Medium· 6.1
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed …

Sunlitjgraph · drawiovia NVD
CVE-2026-36468Medium· 6.1
today

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

Sunlitvia NVD
CVE-2026-36472Medium· 5.2
today

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascrip…

Sunlitvia NVD
CVE-2026-93339Medium· 5.4
today

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

SunlitMetaphor Creations · Dittyvia NVD
CVE-2026-94387Medium· 5.4
today

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can i…

Sunlitaureuserp · aureuserpvia NVD
CVE-2025-71419Medium· 5.4
today

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script …

Sunlituvdesk · core-frameworkvia NVD
CVE-2026-94372Medium· 6.3
today

MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page

MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an …

SunlitMISP · MISPvia NVD
CVE-2026-94211Low· 2.4PoC
today

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

TwilightHyve5 · Leantimevia NVD
CVE-2026-94373Medium· 6.3
today

MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component

MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Be…

SunlitMISP · MISPvia NVD
CVE-2026-94210Low· 3.5
today

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

SunlitHyve5 · Leantimevia NVD
CVE-2026-91921Medium· 5.1
today

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the w…

Sunlit1millionbot · AI Chatbot Platform (SaaS) de 1millionbot.via NVD
CVE-2026-94277Medium· 6.3
today

MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding

MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission …

SunlitMISP · MISPvia NVD
CVE-2026-94150Low· 2.4
today

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

SunlitOmega Solution · HRM OSEPSS 0.20%via NVD
CVE-2026-94145Low· 3.5PoC
today

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

Twilightxuxueli · xxl-jobEPSS 0.19%via NVD
CVE-2026-94045Low· 3.5
yesterday

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argumen…

Sunlitnewbee-ltd · newbee-mallEPSS 0.39%via NVD
CVE-2026-94035Medium· 4.3
yesterday

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.28%via NVD
CVE-2026-94034Low· 3.5
yesterday

A vulnerability was found in SourceCodester Drug Recommendation System 1.0

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.20%via NVD
CVE-2026-94033Low· 3.5
yesterday

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txt…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.20%via NVD
CVE-2026-94016Low· 2.4
yesterday

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross si…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.21%via NVD
CVE-2026-93977Low· 3.5
yesterday

A vulnerability was determined in code-projects Assessment Management 1.0

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scri…

Sunlitcode-projects · Assessment ManagementEPSS 0.20%via NVD
CVE-2026-93976Low· 2.4
yesterday

A vulnerability was found in code-projects Assessment Management 1.0

A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remo…

Sunlitcode-projects · Assessment ManagementEPSS 0.21%via NVD
CVE-2026-93975Low· 2.4
yesterday

A vulnerability has been found in code-projects Assessment Management 1.0

A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/passwor…

Sunlitcode-projects · Assessment ManagementEPSS 0.21%via NVD
CVE-2026-14844Medium· 6.8
yesterday

The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform S…

The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform S…

SunlitEPSS 0.24%via NVD
CVE-2026-84223Medium· 6.8
yesterday

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the …

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the …

SunlitEPSS 0.24%via NVD
CVE-2026-93956Low· 3.5PoC
2d ago

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query…

Twilightolivier-ls · PHP-FTSEPSS 0.24%via NVD
CVE-2026-93981Medium· 4.7
2d ago

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

Sunlithonojs · honoEPSS 0.14%via NVD
CVE-2026-5410Medium· 6.4
2d ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_sav…

Sunlitdavidanderson · Redux FrameworkEPSS 0.22%via NVD
CVE-2026-8354Medium· 6.4
2d ago

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping. This makes…

Sunlitcelomitan · Gum Addon for ElementorEPSS 0.20%via NVD
CVE-2026-1256Medium· 6.4
2d ago

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

Sunlitysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.20%via NVD
CWE-79 vulnerabilities (CVEs) · VulnSea