VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-86784Medium· 6.8
1w ago

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript tha…

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript tha…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-86444High· 7.1
1w ago

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who op…

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who op…

▾ TwilightEPSS 0.28%via NVD
CVE-2026-84829High· 8.8
1w ago

The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor…

The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-84088Medium· 6.8
1w ago

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and abov…

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and abov…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-76558Medium· 6.8
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contrib…

The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contrib…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-5920Medium· 6.4
1w ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable secur…

▾ Sunlitboldthemes · Bold Page BuilderEPSS 0.28%via NVD
CVE-2026-18555Medium· 6.1
1w ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient …

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient …

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.23%via NVD
CVE-2026-18595High· 7.2
1w ago

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping.…

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping.…

▾ Twilightwp-lab · WP-Lister Lite for eBayEPSS 0.25%via NVD
CVE-2026-11996Medium· 6.4
1w ago

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcodesupplyco · Advanced PopupsEPSS 0.21%via NVD
CVE-2026-92214Low· 3.5
1w ago

A flaw has been found in a2ui-project a2ui up to 0.10.7

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-c…

▾ Sunlita2ui-project · a2uiEPSS 0.35%via NVD
CVE-2026-15639Critical· 9.3
1w ago

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.39%via NVD
CVE-2026-92257Medium· 5.4
1w ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persis…

▾ SunlitNetcore · NR255-VEPSS 0.24%via NVD
CVE-2026-76873Medium· 5.2
1w ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script throug…

▾ SunlitNetcore · NR255-VEPSS 0.24%via NVD
CVE-2026-76872Medium· 5.4
1w ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. Attacker…

▾ SunlitNetcore · NR255-VEPSS 0.24%via NVD
CVE-2026-76867Medium· 5.4
1w ago

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_…

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_…

▾ SunlitNetcore · NR255-VEPSS 0.24%via NVD
CVE-2026-76864Medium· 4.8
1w ago

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can inject persistent script code t…

▾ SunlitNetcore · NR255-VEPSS 0.25%via NVD
CVE-2026-76858Medium· 4.8
1w ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script through the DDNS configuration path, l…

▾ SunlitNetcore · NR255-VEPSS 0.30%via NVD
CVE-2026-92234Medium· 5.4PoC
1w ago

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute inject…

▾ TwilightWebkul · QloAppsEPSS 0.31%via NVD
CVE-2026-81926Medium· 6.1⚖ disputed
1w ago

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-81927Medium· 5.4⚖ disputed
1w ago

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.image…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81925Medium· 6.1⚖ disputed
1w ago

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a use…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-51133Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

▾ TwilightEPSS 0.91%via NVD
CVE-2026-88743Medium· 6.1PoC
1w ago

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-88742Medium· 5.4
1w ago

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-76704Medium· 5.5
1w ago

A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface

A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Su…

▾ Sunlitarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.33%via NVD
CVE-2026-68534Low· 2.3
1w ago

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then e…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.56%via NVD
CVE-2026-81899High· 7.3
1w ago

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the sub…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.48%via NVD
CVE-2026-12750Medium· 6.4
1w ago

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea…

▾ Sunlitibm · cloud_pak_for_business_automationEPSS 0.17%via NVD
CVE-2026-12749Medium· 6.4
1w ago

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea…

▾ Sunlitibm · cloud_pak_for_business_automationEPSS 0.17%via NVD
CVE-2026-39038Medium· 6.1PoC
1w ago

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

▾ TwilightEPSS 0.25%via NVD
CWE-79 vulnerabilities (CVEs) — page 14 · VulnSea