VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-81898High· 7.5
1w ago

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the sess…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.44%via NVD
CVE-2026-39039Medium· 5.3
1w ago

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

▾ SunlitEPSS 0.37%via NVD
CVE-2026-39040Medium· 5.4
1w ago

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-18113High· 7.5
1w ago

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
1w ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81896Medium· 5.4⚖ disputed
1w ago

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
1w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-91854Medium· 4.3PoC
1w ago

A vulnerability was identified in code-projects Record Management System 1.0

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remo…

▾ Twilightcode-projects · Record Management SystemEPSS 0.47%via NVD
CVE-2026-91944Medium· 6.1
1w ago

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML

crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can…

▾ Sunlitunclecode · crawl4aiEPSS 0.26%via NVD
CVE-2026-91942Medium· 5.4PoC
1w ago

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute …

▾ Twilightunclecode · crawl4aiEPSS 0.24%via NVD
CVE-2026-87793Medium· 5.1
1w ago

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

▾ SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.51%via NVD
CVE-2026-88618Medium· 6.5PoC
1w ago

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

▾ TwilightEPSS 0.34%via NVD
CVE-2026-90650High· 7.2
1w ago

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping…

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping…

▾ Twilightjetmonsters · MotoPress Hotel BookingEPSS 0.40%via NVD
CVE-2026-15609Medium· 6.4
1w ago

The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient input sanitizati…

The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient input sanitizati…

▾ SunlitQODE · Bridge - Creative Multipurpose WordPress ThemeEPSS 0.19%via NVD
CVE-2026-91922Medium· 6.1PoC
1w ago

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft mali…

▾ Twilightsteedos · steedos-platformEPSS 0.34%via NVD
CVE-2026-18063Medium· 6.4
1w ago

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it …

▾ Sunlitblueglassch · Job PostingsEPSS 0.20%via NVD
CVE-2026-15402Medium· 6.4
1w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, …

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, …

▾ Sunlitarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.25%via NVD
CVE-2026-90850Low· 2.4PoC
1w ago

A vulnerability was detected in PHPGurukul Hostel Management System 3.0

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be lau…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90848Medium· 4.3
1w ago

A weakness has been identified in Governikus AusweisApp up to 2.5.4

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The…

▾ SunlitGovernikus · AusweisAppEPSS 0.45%via NVD
CVE-2026-90845Low· 3.5PoC
1w ago

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. …

▾ TwilightPHPGurukul · Daily Expense Tracker SystemEPSS 0.35%via NVD
CVE-2026-85657Medium· 5.4
1w ago

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

▾ Sunlitpublishpress · Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress AuthorsEPSS 0.24%via NVD
CVE-2026-85575Medium· 6.4
1w ago

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

▾ Sunlitroxnor · ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsEPSS 0.26%via NVD
CVE-2026-44282Medium· 4.8
1w ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…

▾ Sunlitdecidim · decidimEPSS 0.39%via NVD
CVE-2026-62280Medium· 6.1
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl wi…

▾ SunlitOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-55630Low· 0.0
1w ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Officia…

▾ Sunlitkiwitcms · KiwiEPSS 0.42%via NVD
CVE-2026-44203High· 8.3
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.59%via NVD
CVE-2026-44793High· 7.0
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 clust…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.59%via NVD
CVE-2026-55690High· 7.5
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55691High· 8.6PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/Embed…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.48%via NVD
CVE-2026-55650Medium· 4.4PoC
1w ago

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangero…

▾ Twilightouterbase · studioEPSS 0.19%via NVD
CWE-79 vulnerabilities (CVEs) — page 15 · VulnSea