VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2122 CVEsRSS

CVE-2026-18579High· 7.2
2w ago

WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escapin…

▾ Twilightopajaap · WP Photo Album PlusEPSS 0.29%via CVEORG
CVE-2026-89254High· 8.7
2w ago

AVideo CustomizeUser Stored XSS via field_name Parameter

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject …

▾ TwilightWWBN · AVideoEPSS 0.37%via CVEORG
CVE-2026-89249High· 8.7
2w ago

AVideo YPTWallet Stored XSS via CryptoWallet Configuration

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in…

▾ TwilightWWBN · AVideoEPSS 0.37%via CVEORG
CVE-2026-89244Medium· 6.1
2w ago

WWBN AVideo Reflected XSS via Gallery Category getBackURL

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href…

▾ SunlitWWBN · AVideoEPSS 0.26%via CVEORG
CVE-2026-89239Medium· 6.1
2w ago

WWBN AVideo Reflected XSS via Referer Header Comment Breakout

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding…

▾ SunlitWWBN · AVideoEPSS 0.26%via CVEORG
CVE-2026-6642Medium· 6.4
2w ago

Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset fi…

▾ Sunlitdglingren · Media Library AssistantEPSS 0.36%via CVEORG
CVE-2026-54165Medium· 6.4PoC
2w ago

Dobase is an open-source, self-hosted workspace with installable tools

Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A…

▾ Twilightsmgdkngt · dobaseEPSS 0.55%via NVD
CVE-2026-79035Medium· 6.1
2w ago

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-78172Medium· 6.1
2w ago

Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping…

▾ Sunlitthemifyme · Themify – WooCommerce Product FilterEPSS 0.37%via CVEORG
CVE-2026-7298Medium· 6.1
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0.

▾ SunlitIdeaSoft Software Industry and Trade Inc. · Smart E-CommerceEPSS 0.25%via NVD
CVE-2026-14565Medium· 5.4
2w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

▾ SunlitEPSS 0.13%via NVD
CVE-2026-6641Medium· 6.4
2w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the…

▾ Sunlitdglingren · Media Library AssistantEPSS 0.36%via NVD
CVE-2026-89243High· 8.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permi…

▾ MidnightWWBN · AVideoEPSS 0.38%via NVD
CVE-2026-68528Medium· 6.0
2w ago

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the …

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.38%via NVD
CVE-2026-89241Medium· 6.1PoC
2w ago

WWBN AVideo Reflected XSS via confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can c…

▾ TwilightWWBN · AVideoEPSS 0.26%via CVEORG
CVE-2026-82535Medium· 6.1
2w ago

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypas…

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypas…

▾ Sunlitchamilo · chamilo-lmsEPSS 0.47%via NVD
CVE-2026-81911Medium· 5.4
2w ago

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81825High· 7.2
2w ago

Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output esc…

▾ Twilightspecialk · Simple Ajax Chat – Add a Fast, Secure Chat BoxEPSS 0.49%via CVEORG
CVE-2026-89256High· 8.7PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89240Medium· 6.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-84960Medium· 6.1
2w ago

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcbutlerjr · WP-Members Membership PluginEPSS 0.37%via NVD
CVE-2026-77150Medium· 6.1
2w ago

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping.…

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping.…

▾ Sunlitunitecms · Unlimited Elements For ElementorEPSS 0.45%via NVD
CVE-2026-86780Medium· 6.8
2w ago

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting …

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-85678Medium· 6.8
2w ago

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary Java…

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary Java…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-85677High· 8.8
2w ago

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted …

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-83546Medium· 6.8
2w ago

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when t…

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when t…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-83545Medium· 6.8
2w ago

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-17037High· 7.2
2w ago

Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all versions up to, and including, 6.2.0 due to insufficient input sanitizat…

▾ Twilightthemeum · Kirki – Freeform Page Builder, Website Builder & CustomizerEPSS 0.19%via CVEORG
CVE-2026-89255High· 8.7PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated att…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89253High· 8.7PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() val…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CWE-79 vulnerabilities (CVEs) — page 19 · VulnSea