VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-82776Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CONPROSYS PAC Series

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 0.26%via NVD
CVE-2026-82773Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 0.26%via NVD
CVE-2026-82771Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec EC1000 series

Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · ECE1000EPSS 0.24%via NVD
CVE-2026-82769Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · RP-WAH-SR1EPSS 0.24%via NVD
CVE-2026-82767Medium· 5.2
1w ago

Cross-site scripting vulnerability exists in SGA1000

Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · SGA1000EPSS 0.24%via NVD
CVE-2026-88852High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

▾ Twilightregularlabs.com · plg_system_snippetsEPSS 0.42%via NVD
CVE-2026-85196Medium· 5.3
1w ago

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

▾ Sunlitregularlabs.com · plg_system_articlesanywhereEPSS 0.44%via NVD
CVE-2026-82792Medium· 5.2
1w ago

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · CAN-2-WFEPSS 0.24%via NVD
CVE-2026-85190High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A cr…

▾ Twilightregularlabs.com · plg_system_quickindexEPSS 0.42%via NVD
CVE-2026-82790Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · PC-HELPER Wireless I/O DIO-0404RY-LWFEPSS 0.24%via NVD
CVE-2026-78318Medium· 6.1
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

▾ SunlitApache Software Foundation · org.apache.syncope.client.idrepo:syncope-client-idrepo-common-uiEPSS 0.26%via NVD
CVE-2026-90931Medium· 5.4PoC
1w ago

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user incl…

▾ Twilightlaradashboard · laradashboardEPSS 0.24%via NVD
CVE-2026-82019Medium· 4.2PoC
1w ago

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

▾ TwilightTripleLift · video-bundle.jsEPSS 0.29%via NVD
CVE-2026-90957Medium· 5.1
1w ago

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the …

▾ SunlitMISP · MISPEPSS 0.40%via NVD
CVE-2026-90696Low· 3.5PoC
1w ago

A vulnerability was determined in SourceCodester Inventory Management System 1.0

A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipula…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-88853High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not…

▾ Twilightregularlabs.com · plg_system_modalsEPSS 0.42%via NVD
CVE-2026-85191High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected rend…

▾ Twilightregularlabs.com · plg_system_tabsEPSS 0.42%via NVD
CVE-2026-85189High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can re…

▾ Twilightregularlabs.com · plg_system_modalsEPSS 0.42%via NVD
CVE-2026-82795Medium· 5.4
1w ago

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.24%via NVD
CVE-2026-54181Medium· 5.4
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.31%via NVD
CVE-2026-54087High· 7.6
1w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…

▾ TwilightEasyCorp · EasyAdminBundleEPSS 0.40%via NVD
CVE-2026-55847Medium· 6.1
1w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTra…

▾ Sunlitallure-framework · allure2EPSS 0.34%via NVD
CVE-2026-90497Low· 3.5PoC
2w ago

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulati…

▾ TwilightFengoffice · Feng OfficeEPSS 0.33%via NVD
CVE-2026-90489Low· 3.5PoC
2w ago

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed r…

▾ TwilightXuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-90502Low· 3.5PoC
2w ago

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site sc…

▾ Twilightstilleshan · ServerStatusEPSS 0.33%via NVD
CVE-2026-90772High· 7.6PoC
2w ago

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerro…

▾ Midnightamundsen-io · amundsen-frontendEPSS 0.36%via NVD
CVE-2026-90561High· 8.7
2w ago

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store m…

▾ Twilightstrapi · strapiEPSS 0.43%via NVD
CVE-2026-90571Medium· 4.3
2w ago

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performi…

▾ SunlitExrick · xmallEPSS 0.47%via NVD
CVE-2026-90570Low· 2.4
2w ago

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Su…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CVE-2026-90569Low· 2.4
2w ago

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. Th…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CWE-79 vulnerabilities (CVEs) — page 17 · VulnSea