VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-85271Medium· 6.1
1w ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py…

▾ Sunlitopenedx · openedx-platformEPSS 0.35%via NVD
CVE-2026-84108High· 8.1
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.63%via NVD
CVE-2026-84106High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-84074High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-82890Medium· 5.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

▾ SunlitIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-82832Critical· 9.6
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.61%via NVD
CVE-2026-84031Critical· 9.0
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.61%via NVD
CVE-2026-84070High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-93432Medium· 6.1
1w ago

A flaw was found in the Quarkus Qute template engine

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrust…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.42%via NVD
GHSA-9rcc-pmj8-ffhrMedium· 6.1
1w ago

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

▾ Sunlitmediawiki · mediawiki/semantic-media-wikivia GHSA
CVE-2026-91127High· 8.2
1w ago

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…

▾ Twilightfile-viewer · @file-viewer/docEPSS 0.40%via NVD
CVE-2026-84992Medium· 6.1PoC
1w ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

▾ Twilightimzbf · md-editor-v3EPSS 0.33%via NVD
CVE-2026-77616Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.33%via NVD
CVE-2026-77610Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77607Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77606Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. U…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.26%via NVD
CVE-2026-77608Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-1037Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1031Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1029Medium· 5.4
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.16%via NVD
CVE-2026-1025Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.18%via NVD
CVE-2025-61682High· 8.6PoC
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

▾ Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD
CVE-2025-36147Medium· 6.1
1w ago

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web U…

▾ SunlitIBM · Financial Transaction Manager for SWIFT Services for MultiplatformsEPSS 0.20%via NVD
CVE-2026-93505Low· 3.5PoC
1w ago

A vulnerability was found in SveltyCMS 0.0.6

A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-93659High· 8.7PoC
1w ago

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …

▾ Midnightconcretecms-community-store · concretecms-community-store/community_storeEPSS 0.47%via NVD
CVE-2026-79294Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

▾ TwilightEPSS 0.51%via NVD
CVE-2026-18405High· 7.2
1w ago

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insuff…

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insuff…

▾ Twilightjegtheme · Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressEPSS 0.29%via NVD
CVE-2026-90884Medium· 5.4
1w ago

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possib…

▾ Sunlitbrechtvds · WP Recipe MakerEPSS 0.24%via NVD
CVE-2026-15797Medium· 6.4
1w ago

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insuf…

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insuf…

▾ Sunlitdanieliser · Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup BuilderEPSS 0.26%via NVD
CVE-2026-87915High· 7.2PoC
1w ago

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 …

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 …

▾ Midnightdanieliser · Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup BuilderEPSS 0.49%via NVD
CWE-79 vulnerabilities (CVEs) — page 10 · VulnSea