VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-54645Medium· 4.8PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements befor…

▾ Twilightcubecart · v6EPSS 1.1%via NVD
CVE-2026-54644Medium· 6.1PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and on…

▾ Twilightcubecart · v6EPSS 0.90%via NVD
CVE-2026-54506High· 7.6PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in sys…

▾ Midnightgivanz · VvvebEPSS 0.31%via NVD
CVE-2026-53555Medium· 5.1PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the …

▾ Twilightdataease · SQLBotEPSS 0.48%via NVD
GHSA-xjw9-38cr-6372High
1w ago

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

▾ Twilightdjust · djustvia OSV
GHSA-9395-2g46-rj3fHigh
1w ago

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

▾ Twilightdjust · djustvia OSV
CVE-2026-77615High· 8.7PoC
1w ago

Paella Player is a set of libraries to create a multi stream video player

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…

▾ Midnightopencast · opencastEPSS 0.56%via NVD
CVE-2026-76154High· 7.3
1w ago

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

▾ TwilightGrafana · Grafana OSSEPSS 0.35%via NVD
CVE-2026-54355Medium· 5.3PoC
1w ago

MapServer is a system for developing web-based GIS applications

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value…

▾ TwilightMapServer · MapServerEPSS 0.50%via NVD
CVE-2026-45143Critical· 9.0
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue a…

▾ Midnightchamilo · chamilo-lmsEPSS 0.49%via NVD
CVE-2021-3030Medium· 6.1PoC
1w ago

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a vict…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-54521Medium· 6.1
1w ago

FairEmail is a fully featured, open source, privacy-friendly email app for Android

FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incom…

▾ SunlitM66B · FairEmailEPSS 0.33%via NVD
CVE-2026-54253High· 8.2PoC
1w ago

TS3 Manager is modern web interface for maintaining Teamspeak3 servers

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and retu…

▾ Midnightjoni1802 · ts3-managerEPSS 0.28%via NVD
CVE-2026-93296Medium· 5.1
1w ago

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name…

▾ Sunlitmisp · mispEPSS 0.39%via NVD
CVE-2026-92986High· 8.8
1w ago

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters

SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer …

▾ Twilightsiyuan-note · siyuanEPSS 0.82%via NVD
CVE-2026-92985High· 8.8PoC
1w ago

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree

SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scrip…

▾ Midnightsiyuan-note · siyuanEPSS 0.82%via NVD
CVE-2026-63459High· 8.7PoC
1w ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrat…

▾ Midnightvendurehq · vendureEPSS 0.42%via NVD
CVE-2026-92973Medium· 6.1
1w ago

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or termi…

▾ Sunlitpycontribs · ansi2htmlEPSS 0.39%via NVD
CVE-2026-90986High· 7.1
1w ago

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

▾ TwilightCODEPRESS IT Solutions LLC · Visitor Traffic Real Time Statistics ProEPSS 0.25%via NVD
CVE-2026-90887High· 7.1
1w ago

Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

▾ TwilightWP Inventory · wp-inventory-managerEPSS 0.25%via NVD
CVE-2026-78294Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

▾ SunlitDylan Kuhn · geo-mashupEPSS 0.22%via NVD
CVE-2026-66617Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

▾ SunlitPublishPress · organize-seriesEPSS 0.22%via NVD
CVE-2026-66579Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetElements For ElementorEPSS 0.22%via NVD
CVE-2026-66578Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

▾ SunlitProperty Hive · propertyhiveEPSS 0.22%via NVD
CVE-2026-66577Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetSearchEPSS 0.22%via NVD
CVE-2026-66576Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlocks For ElementorEPSS 0.22%via NVD
CVE-2026-66574Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

▾ Sunlitbdthemes · bdthemes-element-pack-liteEPSS 0.22%via NVD
CVE-2026-66573Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTabsEPSS 0.22%via NVD
CVE-2026-66572Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlogEPSS 0.22%via NVD
CVE-2025-15697High· 7.1
1w ago

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attack…

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attack…

▾ TwilightEPSS 0.16%via NVD
CWE-79 vulnerabilities (CVEs) — page 12 · VulnSea