VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2122 CVEsRSS

CVE-2026-88867High· 8.7PoC
2w ago

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Cate…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-88866High· 8.7PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers …

▾ MidnightWWBN · AVideoEPSS 0.45%via NVD
CVE-2026-5399Medium· 6.4
2w ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta…

▾ Sunlitdavidanderson · Redux FrameworkEPSS 0.35%via NVD
CVE-2026-81635Medium· 5.4
2w ago

A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.

A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.

▾ SunlitSHIRASAGI Project · SHIRASAGIEPSS 0.24%via NVD
CVE-2026-0308Low· 1.1
2w ago

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-…

▾ SunlitPalo Alto Networks · Cloud NGFWEPSS 0.27%via NVD
CVE-2026-76562High· 7.2
2w ago

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This m…

▾ Twilightotwthemes · Sidebar Manager LightEPSS 0.40%via NVD
CVE-2026-15820Medium· 6.4
2w ago

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. …

▾ Sunlitbuilderall · Builderall for WordPressEPSS 0.19%via NVD
CVE-2026-87926Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the a…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-87812Medium· 6.8
2w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with eve…

▾ Sunlitsiyuan-note · siyuanEPSS 0.36%via NVD
CVE-2026-19797Medium· 6.1
2w ago

User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group_section' Parameter

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. T…

▾ Sunlitgm_alex · User Access ManagerEPSS 0.21%via CVEORG
CVE-2026-77187Medium· 6.4
2w ago

My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization…

▾ Sunlitjoedolson · My Calendar – Accessible Event ManagerEPSS 0.33%via CVEORG
CVE-2026-87923Medium· 4.3PoC
2w ago

Rizwan17 inventory-management-system List DBOperation.php cross site scripting

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handle…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via CVEORG
CVE-2026-87811High· 7.3PoC
2w ago

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScrip…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-87813High· 7.3PoC
2w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing ma…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-54694Critical· 9.6PoC
2w ago

SkillTree is a micro-learning gamification platform

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…

▾ AbyssalNationalSecurityAgency · skills-serviceEPSS 0.47%via NVD
CVE-2026-18147High· 8.1
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and comple…

▾ TwilightRed Hat · ipaEPSS 0.33%via NVD
CVE-2026-87995High· 8.7PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-…

▾ Midnightopenwebui · open_webuiEPSS 0.42%via NVD
CVE-2026-86772Medium· 5.4
2w ago

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permis…

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permis…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2025-3271Medium· 4.8
2w ago

Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS

Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS

▾ SunlitOpenText™ · Documentum WebtopEPSS 0.23%via NVD
CVE-2026-71802Medium· 5.4
2w ago

A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3

A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the esca…

▾ SunlitEPSS 0.23%via NVD
CVE-2025-24978Low· 3.7
2w ago

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2026-87814High· 7.3
2w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted te…

▾ Twilightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-14989High· 7.2
2w ago

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpl_user_preference' parameter in all versions up to, and including, 4.4.1 due to insufficient input sanit…

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpl_user_preference' parameter in all versions up to, and including, 4.4.1 due to insufficient input sanit…

▾ Twilightwplegalpages · WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeEPSS 0.28%via NVD
CVE-2026-17149Medium· 6.4
2w ago

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute in all versions up to, and including, …

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute in all versions up to, and including, …

▾ Sunlitsaadiqbal · Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredEPSS 0.20%via NVD
CVE-2026-83541Medium· 6.8
2w ago

The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored …

The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored …

▾ SunlitEPSS 0.43%via NVD
CVE-2025-7062Medium· 5.2
2w ago

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malici…

▾ SunlitLumi Education UG · h5p-nodejs-libraryEPSS 0.30%via NVD
CVE-2026-85418Medium· 5.4
2w ago

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rend…

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rend…

▾ SunlitEPSS 0.23%via NVD
CVE-2025-15690Medium· 6.8
2w ago

The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross…

The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-83593High· 7.2
2w ago

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient inpu…

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient inpu…

▾ Twilightquantumcloud · WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesEPSS 0.53%via NVD
CVE-2026-19945Medium· 6.4
2w ago

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it po…

▾ Sunlitthemeum · WP CrowdfundingEPSS 0.22%via NVD
CWE-79 vulnerabilities (CVEs) — page 21 · VulnSea