VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-90568Low· 3.5
2w ago

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of …

▾ Sunlitmoxi624 · Mogu Blog v2EPSS 0.33%via NVD
CVE-2026-90567Low· 3.5
2w ago

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of th…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVE-2026-90564Low· 3.5
2w ago

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVE-2026-90563Low· 3.5
2w ago

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out rem…

▾ Sunlitmaliangnansheng · bbs-springbootEPSS 0.36%via NVD
CVE-2026-90529Low· 3.5
2w ago

A vulnerability has been found in DataEase up to 2.10.25/2.10.26

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-90528Low· 3.5
2w ago

A flaw has been found in TDuckApp tduck-platform up to 5.3

A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argu…

▾ SunlitTDuckApp · tduck-platformEPSS 0.35%via NVD
CVE-2026-90527Medium· 4.3
2w ago

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.47%via NVD
CVE-2025-64059Low· 1.8PoC
2w ago

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

▾ Twilightgetgrav · GravEPSS 0.30%via NVD
CVE-2026-90602Low· 3.5
2w ago

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cro…

▾ SunlitAnil-matcha · Open-Generative-AIEPSS 0.36%via NVD
CVE-2026-90583Medium· 4.3PoC
2w ago

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulatio…

▾ Twilightkagisearch · smallwebEPSS 0.49%via NVD
CVE-2026-88793High· 8.8
2w ago

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it,…

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it,…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-85129High· 8.8
2w ago

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauth…

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauth…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-74933High· 8.8
2w ago

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configurat…

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configurat…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-89268Medium· 5.4
2w ago

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malic…

▾ SunlitWebkul · QloAppsEPSS 0.30%via NVD
CVE-2026-87888High· 8.0
2w ago

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an …

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an …

▾ TwilightEPSS 0.41%via NVD
CVE-2026-86790Medium· 6.8
2w ago

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored C…

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored C…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-10148Medium· 6.4
2w ago

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and o…

▾ Sunlitmelograno · Booking for Appointments and Events Calendar – AmeliaEPSS 0.24%via NVD
CVE-2026-83532Medium· 6.8
2w ago

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web script…

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web script…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-82847Medium· 6.8
2w ago

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks…

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-81742High· 8.8
2w ago

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated …

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-81429High· 7.1
2w ago

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

▾ TwilightEPSS 0.13%via NVD
CVE-2026-90443Medium· 5.3
2w ago

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a lin…

▾ SunlitCISA · MalcolmEPSS 0.56%via NVD
CVE-2026-81918Medium· 4.8
2w ago

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.25%via NVD
CVE-2026-81917Medium· 5.4
2w ago

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-6640Medium· 6.4
2w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. …

▾ Sunlitdglingren · Media Library AssistantEPSS 0.42%via NVD
CVE-2026-77490Medium· 6.1
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.41%via NVD
CVE-2026-62138Medium· 6.5
2w ago

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

▾ SunlitVisual Composer · visualcomposerEPSS 0.22%via NVD
CVE-2026-62111Medium· 6.5
2w ago

WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.

▾ SunlitIdo Kobelkowsky · simple-paymentEPSS 0.22%via CVEORG
CVE-2026-62110Medium· 6.5
2w ago

WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

▾ Sunlitboldthemes · bold-page-builderEPSS 0.22%via CVEORG
CVE-2026-18579High· 7.2
2w ago

WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escapin…

▾ Twilightopajaap · WP Photo Album PlusEPSS 0.29%via CVEORG
CWE-79 vulnerabilities (CVEs) — page 18 · VulnSea