VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2122 CVEsRSS

CVE-2026-84293High· 7.2
2w ago

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and outp…

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and outp…

▾ Twilightaddonsorg · Repeater Fields for Gravity FormsEPSS 0.51%via NVD
CVE-2026-77186Medium· 6.4
2w ago

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output…

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output…

▾ Sunlitjoedolson · My Calendar – Accessible Event ManagerEPSS 0.36%via NVD
CVE-2026-7804Medium· 6.1
2w ago

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output esca…

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output esca…

▾ Sunlitwoobewoo · Product Filter for WooCommerce by WBWEPSS 0.46%via NVD
CVE-2026-75966Medium· 6.4
2w ago

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and o…

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and o…

▾ Sunliteteubert · Podlove Podcast PublisherEPSS 0.45%via NVD
CVE-2026-13359High· 7.2
2w ago

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…

▾ Twilightbestweblayout · Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPressEPSS 0.24%via NVD
CVE-2026-13709Medium· 6.4
2w ago

The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…

The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…

▾ Sunlitiqonicdesign · Graphina – Charts and Graphs For ElementorEPSS 0.19%via NVD
CVE-2026-87632Medium· 4.3
2w ago

Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-85982Critical· 9.0
2w ago

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to …

▾ MidnightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.40%via NVD
CVE-2026-78742Medium· 6.1PoC
2w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78741Medium· 6.1PoC
2w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78738Medium· 6.1PoC
2w ago

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-85630Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.24%via NVD
CVE-2026-85485Medium· 6.1⚖ disputed
2w ago

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-85484Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.33%via NVD
CVE-2026-19872Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-84942High· 8.7
2w ago

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser…

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser…

▾ TwilightAWS · Amazon OpenSearch ServiceEPSS 0.54%via NVD
CVE-2026-76002Medium· 6.1
2w ago

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of …

▾ Sunlitadobe · coldfusionEPSS 0.43%via NVD
CVE-2026-75993High· 8.5
2w ago

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's ac…

▾ Twilightadobe · coldfusionEPSS 0.45%via NVD
CVE-2026-79905Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.39%via NVD
CVE-2026-75736Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.39%via NVD
CVE-2026-75720Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2026-75717Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2026-75714Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2026-75693Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2026-75670Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2025-64588Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.28%via NVD
CVE-2025-64542Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.26%via NVD
CVE-2026-75737Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.39%via NVD
CVE-2026-75727Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.39%via NVD
CVE-2026-75724Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CWE-79 vulnerabilities (CVEs) — page 22 · VulnSea