VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-84763High· 7.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-81295High· 7.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-85207Low· 3.5
3w ago

A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0

A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The atta…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-84812High· 7.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-84774Medium· 6.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-81773High· 7.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-81281Medium· 6.5
3w ago

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-56126Medium· 5.4
3w ago

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-85159Medium· 5.4
3w ago

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unau…

▾ SunlitEPSS 0.29%via NVD
GHSA-99rq-75j6-5j9fHigh· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-81201Medium· 6.1
3w ago

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

▾ Sunlitmonster_menus_project · monster_menusEPSS 0.26%via NVD
CVE-2026-84701Medium· 5.4
3w ago

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in …

▾ SunlitEPSS 0.30%via NVD
CVE-2026-75134Medium· 6.4
3w ago

SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly p…

SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly p…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-84648High· 8.8
3w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in co…

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in co…

▾ Twilightjenkins · jenkinsEPSS 0.58%via NVD
CVE-2026-81167Medium· 4.8
3w ago

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.

▾ Sunlitaddress_suggestion_project · address_suggestionEPSS 0.24%via NVD
CVE-2026-84695High· 8.7
3w ago

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload S…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-18986Medium· 4.8
3w ago

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.

▾ Sunlitentity_browser_project · entity_browserEPSS 0.14%via NVD
GHSA-cp6q-959q-f8rhMedium
3w ago

Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

▾ Sunlittiptap · @tiptap/corevia GHSA
CVE-2026-84232Medium· 5.4
3w ago

Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-D…

▾ SunlitRed Hat · ansible-automation-platform-24/hub-rhel8EPSS 0.24%via CVEORG
CVE-2026-84370High· 8.2
3w ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions …

▾ Twilightsvgo · svgoEPSS 0.53%via NVD
CVE-2026-84369Medium· 6.1
3w ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions …

▾ Sunlitsvgo · svgoEPSS 0.43%via NVD
CVE-2026-83607High· 8.1
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(tagName) stores…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.61%via NVD
CVE-2026-83605High· 8.1
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute() calls the priva…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.61%via NVD
CVE-2026-84477Medium· 5.4
3w ago

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS pa…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-84193None
3w ago

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attac…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-84192High· 7.1
3w ago

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitra…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-84191Medium· 6.1
3w ago

LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization

LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attacker…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-84189High· 8.1
3w ago

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars()

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An admi…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-73524Medium· 6.1
3w ago

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-84188Medium· 4.8
3w ago

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrato…

▾ SunlitEPSS 0.25%via NVD
CWE-79 vulnerabilities (CVEs) — page 30 · VulnSea