VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-50190None
1mo ago

Shaarli is a personal bookmarking service

Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` i…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-55491Medium· 5.4
1mo ago

BigBlueButton is an open-source virtual classroom

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged u…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-73259Medium· 5.4
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-73254Medium· 5.4
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLI…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-77643Medium· 4.4
1mo ago

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet()

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a m…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-77506Medium· 4.8
1mo ago

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-68921Medium· 4.7
1mo ago

DiceBear is an avatar library for designers and developers

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, whil…

▾ Sunlitdicebear · @dicebear/coreEPSS 0.29%via NVD
CVE-2026-54263High· 7.3
1mo ago

Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

▾ Twilightwagtail · wagtailEPSS 0.36%via GHSA
CVE-2026-75526Medium· 4.4
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values…

▾ Sunlitdjango-cms · django-cmsEPSS 0.26%via NVD
GHSA-7mpf-4465-7fc2Low· 2.0
1mo ago

Winter: Stored XSS through Backend List widget image columns

Winter: Stored XSS through Backend List widget image columns

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-5cwr-5jxg-pcf6Medium· 4.5
1mo ago

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-hq84-x37p-j6q5Medium· 4.5
1mo ago

Winter: Reflected XSS through the search query parameter in the backend Table widget

Winter: Reflected XSS through the search query parameter in the backend Table widget

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
CVE-2026-49245Low· 3.7
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowin…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.25%via NVD
CVE-2026-67189Medium· 6.1
1mo ago

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization…

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization…

▾ SunlitEPSS 1.2%via NVD
CVE-2026-54743None
1mo ago

Lemmy is a link aggregator and forum for the fediverse

Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars thr…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-68900High· 7.6
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText an…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-55085Critical· 9.6
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated m…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-64851None
1mo ago

Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode

Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode Core passes shortcode syntax through Security::detectXss() because it…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-61607Medium· 4.6
1mo ago

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API plugin POST /api/v1/media pipeline in HandlesMediaUploads::processUploadedFile() validates an SVG filen…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-40508Medium· 5.4
1mo ago

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitra…

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitra…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-40507Medium· 6.1
1mo ago

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-61807Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-si…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-55090High
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute esc…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.55%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.58%via NVD
CVE-2026-75838Medium· 6.1
1mo ago

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that ex…

▾ SunlitRed Hat · Red Hat Ceph Storage 9EPSS 0.30%via NVD
CVE-2026-75626Critical· 9.3PoC
1mo ago

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute script…

▾ Abyssalsmicallef · spiderfootEPSS 0.33%via NVD
CVE-2026-61696Medium· 6.3
1mo ago

Forem is open source software for building communities

Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitted through feedback_message[message] is stored without sanitization and rendered in app/…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-73426Medium· 4.6
1mo ago

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can …

▾ SunlitRed HatEPSS 0.32%via NVD
CVE-2026-45733High· 8.3
1mo ago

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute…

▾ TwilightEPSS 0.43%via NVD
CWE-79 vulnerabilities (CVEs) — page 34 · VulnSea