VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-55692High· 7.5PoC
1w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-18116Medium· 6.1
1w ago

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user per…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.15%via NVD
CVE-2026-81900Medium· 6.1
1w ago

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with e…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-90835Low· 3.5PoC
1w ago

A flaw has been found in michaelliao itranswarp up to 2.19

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack…

▾ Twilightmichaelliao · itranswarpEPSS 0.35%via NVD
CVE-2026-18117High· 7.3
1w ago

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization

Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticate…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.31%via NVD
CVE-2026-91146Medium· 6.1
1w ago

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript:…

▾ Sunlitjointakahe · takaheEPSS 0.34%via NVD
CVE-2026-13276Medium· 6.1
1w ago

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

▾ SunlitIBM · Verify Identity AccessEPSS 0.24%via NVD
CVE-2026-81903Medium· 5.4
1w ago

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.32%via NVD
CVE-2026-86898Medium· 5.4
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.

▾ Sunlitapple · safariEPSS 0.25%via NVD
CVE-2026-7884Medium· 5.4
1w ago

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account m…

▾ SunlitIBM · Cognos AnalyticsEPSS 0.23%via NVD
CVE-2026-78415Medium· 5.4
1w ago

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

▾ SunlitIBM · Sterling Secure ProxyEPSS 0.31%via NVD
CVE-2026-16186Medium· 5.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-18119Critical· 9.0⚖ disputed
1w ago

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administra…

▾ Midnightconcretecms · concrete_cmsEPSS 0.31%via NVD
CVE-2026-91021Medium· 5.4
1w ago

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allow…

▾ SunlitTrilium · Trillium NotesEPSS 0.23%via NVD
CVE-2026-90943High· 8.7
1w ago

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies…

▾ Twilightparallax · parallax/filament-commentsEPSS 0.43%via NVD
CVE-2026-90795Medium· 4.3PoC
1w ago

A vulnerability was determined in itsourcecode Loan Management System 1.0

A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible…

▾ Twilightitsourcecode · Loan Management SystemEPSS 0.47%via NVD
CVE-2026-4103Medium· 6.4
1w ago

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affec…

▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.30%via NVD
CVE-2026-90604Low· 3.5PoC
1w ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is …

▾ TwilightTotolink · A3002MUEPSS 0.35%via NVD
CVE-2026-90615Medium· 4.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The atta…

▾ TwilightSourceCodester · Class and Exam Timetabling SystemEPSS 0.47%via NVD
CVE-2025-63842Medium· 5.4PoC
1w ago

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice…

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice…

▾ TwilightRepetico · web backendEPSS 0.23%via NVD
CVE-2023-28148High· 7.2
1w ago

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

▾ TwilightPaessler · PRTG Network MonitorEPSS 0.21%via NVD
CVE-2026-90695Low· 3.5PoC
1w ago

A vulnerability was found in SourceCodester Inventory Management System 1.0

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation re…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-82796Medium· 5.4
1w ago

SolarView Compact contains a cross-site scripting vulnerability in Image Management

SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.24%via NVD
CVE-2024-23176Medium· 5.4PoC
1w ago

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

▾ TwilightRed Hat · MassMessageEPSS 0.21%via NVD
CVE-2023-51769Medium· 6.1
1w ago

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

▾ SunlitFrappe · FrappeEPSS 0.19%via NVD
CVE-2026-90694Low· 3.5PoC
1w ago

A vulnerability has been found in SourceCodester Inventory Management System 1.0

A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Custo…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-82788Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CPSL-08P1EN

Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · CPSL-08P1ENEPSS 0.26%via NVD
CVE-2026-82781Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in CONPROSYS nano Series

Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.24%via NVD
CVE-2026-82763Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · FXA5000EPSS 0.24%via NVD
CVE-2026-85195High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options b…

▾ Twilightregularlabs.com · plg_system_articlesanywhereEPSS 0.42%via NVD
CWE-79 vulnerabilities (CVEs) — page 16 · VulnSea