VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-84371Medium· 5.4
3w ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.30%via NVD
GHSA-f8fg-pg57-v4j8High· 7.2
3w ago

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

▾ Twilightleague · league/commonmarkvia GHSA
CVE-2026-58191Medium· 6.5PoC
3w ago

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

▾ Twilightappium · @appium/base-driverEPSS 0.56%via GHSA
CVE-2026-82868Medium· 6.1
3w ago

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded script…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-82867Medium· 6.1
3w ago

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with c…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-82865Medium· 4.4
3w ago

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can i…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-82881Medium· 5.4
3w ago

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat resp…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-82396Medium· 5.4
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and it…

▾ Sunlitsulu · sulu/suluEPSS 0.30%via NVD
CVE-2026-81887Medium
3w ago

Livewire is a full-stack framework for Laravel

Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __p…

▾ Sunlitlivewire · livewire/livewireEPSS 0.68%via NVD
CVE-2026-54179Medium· 4.4
3w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/Si…

▾ Sunlitbackpack · backpack/crudEPSS 0.26%via NVD
CVE-2026-82554Medium· 4.3
4w ago

A flaw has been found in SourceCodester Queue Management System 1.0

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attac…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-82654High· 8.9
4w ago

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views doc…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-82653High· 8.9
4w ago

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar pac…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-82646Medium· 6.1
4w ago

WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters

WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an e…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-82642High· 8.8
4w ago

Readest is an open-source e-book reader built on Tauri

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/sr…

▾ TwilightEPSS 0.66%via NVD
CVE-2026-82488Low· 3.5
4w ago

A vulnerability was identified in Beetel 450TC3 01.00.00_01

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82483Low· 3.5
4w ago

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scr…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82482Low· 3.5
4w ago

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Bio…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82451Medium· 6.1
4w ago

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in…

▾ Sunlitgetformwork · FormworkEPSS 0.36%via NVD
CVE-2026-76546Medium· 6.8
4w ago

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewin…

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewin…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-76798Medium· 6.3
1mo ago

The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context

The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector …

▾ Sunlitmongodb · mongosql_transition_readiness_toolEPSS 0.29%via NVD
CVE-2026-76794Medium· 4.6
1mo ago

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user …

▾ Sunlitmongodb · mongosql_transition_readiness_toolEPSS 0.23%via NVD
CVE-2026-78071High· 7.5PoC
1mo ago

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

▾ Midnightdigital-peak.com · DP Calendar extension for JoomlaEPSS 0.42%via NVD
CVE-2026-82090NonePoC
1mo ago

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

▾ TwilightEPSS 0.44%via NVD
CVE-2026-82089None
1mo ago

The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

▾ SunlitEPSS 0.53%via NVD
CVE-2026-50980Medium· 6.1PoC
1mo ago

Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record

Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record

▾ TwilightEPSS 0.40%via NVD
CVE-2026-38725Medium· 5.4
1mo ago

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and ren…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-37710Medium· 6.1
1mo ago

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

▾ SunlitEPSS 0.50%via NVD
CVE-2026-82123Medium· 6.5
1mo ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-3129Medium· 6.4
1mo ago

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` …

▾ SunlitEPSS 0.33%via NVD
CWE-79 vulnerabilities (CVEs) — page 31 · VulnSea