VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-85593Medium· 5.4
3w ago

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated user…

▾ Sunlitthorsten · phpMyFAQEPSS 0.24%via NVD
CVE-2026-85577Medium· 5.4
3w ago

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-85541Medium· 5.4
3w ago

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

▾ SunlitEPSS 0.28%via NVD
CVE-2026-85613High· 8.2PoC
3w ago

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicio…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.40%via NVD
CVE-2026-73848Medium· 6.9
3w ago

Emlog is an open source website building system

Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslas…

▾ Sunlitemlog · emlogEPSS 0.44%via NVD
CVE-2026-79418High· 8.7PoC
3w ago

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers …

▾ Midnightemxtecnologia · gestao_x_business_suiteEPSS 0.38%via NVD
CVE-2026-8447Medium· 6.1
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

▾ Sunlitlangflow · langflowEPSS 0.30%via NVD
CVE-2026-19727Medium· 6.1
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Auto…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-14466Medium· 4.3
3w ago

It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices a…

It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices a…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-77818Medium· 6.1PoC
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Auto…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-19057Medium· 5.4
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu System: before …

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu System: before …

▾ SunlitEPSS 0.13%via NVD
CVE-2026-18957Medium· 5.4
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: before 20260903211448.

▾ SunlitEPSS 0.16%via NVD
CVE-2026-85406Low· 3.5PoC
3w ago

A vulnerability has been found in Eleveo Quality Management 9.7.0

A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possibl…

▾ TwilightEleveo · Quality ManagementEPSS 0.33%via NVD
CVE-2026-85229Medium· 6.1
3w ago

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. …

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. …

▾ SunlitApache Software Foundation · Apache SkyWalkingEPSS 0.25%via NVD
CVE-2026-80190Medium· 6.1
3w ago

Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recomm…

Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recomm…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-80180Medium· 6.1
3w ago

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-27086Medium· 6.5
3w ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-79419High· 8.7PoC
3w ago

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao…

▾ Midnightemxtecnologia · gestao_x_business_suiteEPSS 0.38%via NVD
CVE-2026-85600Medium· 5.4
3w ago

Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into transla…

Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into transla…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-85599High· 7.2PoC
3w ago

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can i…

▾ Midnightgetgrav · grav-plugin-shortcode-coreEPSS 0.26%via NVD
CVE-2026-85598Medium· 6.4
3w ago

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious …

▾ Sunlitgetgrav · gravEPSS 0.26%via NVD
CVE-2026-85230Medium· 5.4
3w ago

A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration

A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a…

▾ Sunlitmisp-project · mispEPSS 0.29%via NVD
CVE-2026-85227Medium· 6.1
3w ago

MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder

MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML e…

▾ Sunlitmisp-project · mispEPSS 0.25%via NVD
CVE-2026-56128Medium· 5.4
3w ago

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is store…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-56127Medium· 5.4
3w ago

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-85061Critical· 10.0
3w ago

MapLibre GL JS is an interactive vector tile map library for web browsers

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collec…

▾ Midnightmaplibre-gl · maplibre-glEPSS 0.52%via NVD
CVE-2026-82024Medium· 5.4
3w ago

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz …

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz …

▾ SunlitEPSS 0.24%via NVD
CVE-2026-85158Medium· 5.4
3w ago

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arb…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-85453Medium· 6.1
3w ago

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the b…

▾ Sunlitthemoos · core-moosEPSS 0.34%via NVD
CVE-2026-85302Medium· 6.5
3w ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a …

▾ SunlitEPSS 0.22%via NVD
CWE-79 vulnerabilities (CVEs) — page 29 · VulnSea