VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

GHSA-9pr6-8r9w-wvmjCritical· 8.7
1mo ago

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-993v-76jg-67xrMedium· 5.4
1mo ago

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-q8cg-5m48-5c25Medium· 7.6
1mo ago

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-52873Medium· 6.9
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and regis…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-30250Medium· 6.1
1mo ago

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code

▾ SunlitEPSS 0.36%via NVD
CVE-2026-75834Medium· 5.4
1mo ago

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.26%via NVD
CVE-2026-45116High· 8.7
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fi…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-45115High· 8.7
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Bud…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-75831High· 7.6
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…

▾ Twilightgetgrav · getgrav/gravEPSS 0.35%via NVD
CVE-2026-75828High· 8.7
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…

▾ Twilightgetgrav · getgrav/gravEPSS 0.39%via NVD
CVE-2026-75107Medium· 5.4PoC
1mo ago

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HT…

▾ Twilightgetgrav · gravEPSS 0.24%via NVD
CVE-2026-74908Medium· 4.6
1mo ago

Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized

Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with a…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-41921Medium· 5.4
1mo ago

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input throug…

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input throug…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-54347High· 8.7
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content…

▾ Twilightfroxlor · froxlor/froxlorEPSS 0.42%via NVD
GHSA-7cj5-v4pp-v632Medium· 4.8
1mo ago

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

▾ Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7gww-x7fh-jf9jHigh· 8.1
1mo ago

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

▾ Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-55839High· 8.7
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…

▾ Twilightkestra · io.kestra:kestraEPSS 0.43%via NVD
CVE-2026-52854High· 8.6
1mo ago

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays p…

▾ Twilightmediawiki · mediawiki/mapsEPSS 0.58%via NVD
CVE-2026-33437High· 8.1
1mo ago

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title a…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-55674Critical· 9.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary H…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-75048High· 8.2
1mo ago

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

▾ Twilightjetbrains · youtrackEPSS 0.32%via NVD
CVE-2026-75059Medium· 4.4
1mo ago

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

▾ Sunlitjetbrains · pycharmEPSS 0.18%via NVD
CVE-2026-13202High· 7.3
1mo ago

HTML Injection in OTDS Swagger UI

A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2.

▾ TwilightOpenText · Opentext Directory ServicesEPSS 0.44%via CVEORG
CVE-2026-50771Medium· 6.1
1mo ago

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.

▾ SunlitEPSS 0.31%via NVD
CVE-2026-74999Medium· 5.4
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

▾ Sunlitroundcube · webmailEPSS 0.30%via NVD
CVE-2026-74998High· 7.2
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

▾ Twilightroundcube · webmailEPSS 0.44%via NVD
CVE-2026-63670Medium· 6.1
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a li…

▾ Sunlitsanitize-html · sanitize-htmlEPSS 0.33%via NVD
CVE-2026-15726Medium· 6.4
1mo ago

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it po…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15066Medium· 6.4
1mo ago

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it pos…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-15009Medium· 6.1
1mo ago

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 du…

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 du…

▾ SunlitEPSS 0.39%via NVD
CWE-79 vulnerabilities (CVEs) — page 35 · VulnSea