VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2124 CVEsRSS

CVE-2026-71357Medium· 5.4
2w ago

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's bro…

▾ Sunlitadobe · experience_managerEPSS 0.36%via NVD
CVE-2025-64838Medium· 5.4
2w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ Sunlitadobe · experience_managerEPSS 0.28%via NVD
CVE-2026-78997Critical· 9.3PoC
2w ago

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a spe…

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-76201Critical· 9.3
2w ago

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when …

▾ Midnightadobe · commerceEPSS 0.74%via NVD
CVE-2026-76200Critical· 9.3
2w ago

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when …

▾ Midnightadobe · magentoEPSS 0.74%via NVD
CVE-2026-69642Medium· 6.5
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · skype_for_business_serverEPSS 0.41%via NVD
CVE-2026-63523Medium· 6.5
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · skype_for_business_serverEPSS 0.55%via NVD
CVE-2026-81824Medium· 4.7
2w ago

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

▾ SunlitAVEVA · Pipeline Integrity MonitorEPSS 0.37%via NVD
CVE-2026-69690Medium· 4.6
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · sharepoint_serverEPSS 0.40%via NVD
CVE-2026-69615Low· 3.5
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · sharepoint_serverEPSS 0.40%via NVD
CVE-2026-69417High· 7.3
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · sharepoint_serverEPSS 0.45%via NVD
CVE-2026-69402High· 7.3
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · sharepoint_serverEPSS 0.45%via NVD
CVE-2026-69356Critical· 9.3
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.77%via NVD
CVE-2026-86668Medium· 4.3PoC
2w ago

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.47%via NVD
CVE-2026-52307Medium· 5.4PoC
2w ago

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

▾ TwilightEPSS 0.29%via NVD
CVE-2026-86738High· 8.7
2w ago

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS paylo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.49%via NVD
CVE-2026-86644Low· 3.5PoC
2w ago

A vulnerability was determined in star7th showdoc up to 3.9.1

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross s…

▾ Twilightstar7th · showdocEPSS 0.36%via NVD
CVE-2026-78838Medium· 6.5PoC
2w ago

A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload in…

A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload in…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-73319Medium· 6.1PoC
2w ago

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that by…

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that by…

▾ Twilightxenforo · xenforoEPSS 0.41%via NVD
CVE-2026-86712High· 8.8
2w ago

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that writ…

▾ Twilightsiyuan-note · siyuanEPSS 0.71%via NVD
CVE-2026-86550Medium· 6.5
2w ago

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that …

▾ SunlitZTE · NebulaOSEPSS 0.46%via NVD
CVE-2026-76931Medium· 6.4
2w ago

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitdylanjkotze · Zephyr Project ManagerEPSS 0.33%via NVD
CVE-2026-12230Medium· 6.4
2w ago

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insuffi…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insuffi…

▾ Sunlitthimpress · LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesEPSS 0.20%via NVD
CVE-2026-84820High· 7.1
2w ago

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

▾ TwilightUnlimited Elements · unlimited-elements-for-elementorEPSS 0.25%via NVD
CVE-2026-84818High· 7.1
2w ago

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

▾ Twilight100plugins · open-user-mapEPSS 0.25%via NVD
CVE-2026-84817High· 7.1
2w ago

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

▾ TwilightCrocoblock · jetformbuilderEPSS 0.25%via NVD
CVE-2026-81798High· 7.1
2w ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.

▾ TwilightEasy Appointments · easy-appointmentsEPSS 0.25%via NVD
CVE-2026-58113Medium· 6.1
2w ago

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607)

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected appli…

▾ SunlitSiemens · Teamcenter V2412EPSS 0.38%via NVD
CVE-2026-78325Medium· 6.9
2w ago

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Goo…

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Goo…

▾ SunlitStandard Notes · Standard NotesEPSS 0.12%via NVD
CVE-2026-86491Low· 3.5
2w ago

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

▾ SunlitJetBrains · YouTrackEPSS 0.24%via NVD
CWE-79 vulnerabilities (CVEs) — page 26 · VulnSea