VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-54049High· 8.7
1mo ago

Sakai Conversations has a Stored XSS Issue

Sakai Conversations has a Stored XSS Issue

▾ Twilightsakaiproject · org.sakaiproject.conversations:sakai-conversations-implvia GHSA
CVE-2026-77027None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.

Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-4561Medium· 6.4
1mo ago

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due …

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-4559Medium· 6.4
1mo ago

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output…

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-66917NonePoC
1mo ago

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

▾ TwilightEPSS 0.52%via NVD
CVE-2026-69238Low· 3.5
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS E…

▾ Sunlitesri · portal_for_arcgisEPSS 0.24%via NVD
CVE-2026-69237Low· 3.8
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterp…

▾ Sunlitesri · portal_for_arcgisEPSS 0.29%via NVD
CVE-2026-69230Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

▾ Sunlitesri · portal_for_arcgisEPSS 0.24%via NVD
CVE-2026-69229Medium· 5.4
1mo ago

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enter…

▾ Sunlitesri · portal_for_arcgisEPSS 0.27%via NVD
CVE-2026-69235Medium· 6.1
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users wo…

▾ Sunlitesri · portal_for_arcgisEPSS 0.30%via NVD
CVE-2026-69234Medium· 6.1
1mo ago

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary …

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary …

▾ Sunlitesri · portal_for_arcgisEPSS 0.33%via NVD
CVE-2026-69233Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s …

▾ Sunlitesri · portal_for_arcgisEPSS 0.27%via NVD
CVE-2026-69232Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

▾ Sunlitesri · portal_for_arcgisEPSS 0.33%via NVD
CVE-2026-69231Medium· 5.5
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

▾ Sunlitesri · portal_for_arcgisEPSS 0.33%via NVD
CVE-2026-69236Medium· 6.1
1mo ago

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browse…

▾ Sunlitesri · portal_for_arcgisEPSS 0.30%via NVD
CVE-2026-53529None
1mo ago

LeafWiki is a self-hosted wiki

LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-53468Medium· 4.6
1mo ago

Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites

Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the page metadata fields (`og:title` and `…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-33240High· 8.8
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.47%via NVD
CVE-2026-31880High· 8.0
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.43%via NVD
CVE-2026-31803High· 8.0
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.43%via NVD
CVE-2026-30890High· 8.0
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.43%via NVD
CVE-2026-30865High· 7.1
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-30826High· 8.0
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.43%via NVD
CVE-2026-30819High· 7.3
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This i…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-61824High· 8.2
1mo ago

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

▾ Twilightdefuddle · defuddleEPSS 0.41%via GHSA
CVE-2026-63135High· 8.2
1mo ago

YOURLS is a self-hosted, customizable URL shortener written in PHP

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the …

▾ Twilightyourls · yourls/yourlsEPSS 0.43%via NVD
GHSA-8hgv-xc77-jmcrMedium
1mo ago

Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-43980Medium· 6.3
1mo ago

Malla is a web analyzer for Meshtastic networks based on MQTT data

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered int…

▾ Sunlitmalla · mallaEPSS 0.33%via NVD
CVE-2026-54505None
1mo ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx…

▾ SunlitEPSS 0.58%via NVD
CVE-2026-49436High· 7.3
1mo ago

LinkAce is a self-hosted archive to collect website links

LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:`…

▾ TwilightEPSS 0.37%via NVD
CWE-79 vulnerabilities (CVEs) — page 33 · VulnSea