VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-15002High· 7.2
1mo ago

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-12477Medium· 4.4
1mo ago

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output es…

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output es…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-11780Medium· 6.4
1mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input san…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input san…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-2487Medium· 4.4
1mo ago

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible fo…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19922Low· 3.5
1mo ago

A security flaw has been discovered in code-projects Online Shopping System 1.0

A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scr…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-73053Critical· 9.0
1mo ago

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the rend…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-73052Critical· 9.0
1mo ago

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrar…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-73050Critical· 9.0
1mo ago

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by includ…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-73044Critical· 9.0
1mo ago

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that br…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-73043Critical· 9.0
1mo ago

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HT…

▾ MidnightEPSS 0.64%via NVD
CVE-2026-73042Critical· 9.0
1mo ago

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-73041Critical· 9.0
1mo ago

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with fu…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-19916Low· 3.5
1mo ago

A vulnerability was detected in code-projects Online Food Order System 1.0

A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Rem…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-19904Low· 2.4
1mo ago

A vulnerability was found in SourceCodester Online Book Store System 1.0

A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross …

▾ SunlitEPSS 0.37%via NVD
GHSA-cgvr-f65r-pjv3Medium· 5.4
1mo ago

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-72832Medium· 5.4
1mo ago

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via NVD
CVE-2026-73038Medium· 6.1
1mo ago

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-73428Medium· 4.6
1mo ago

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted into the editor. HTMLParser processes a mock attachment in a `<s…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-73650High· 8.2
1mo ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 throu…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-73648None
1mo ago

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even t…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-73531Medium· 6.1
1mo ago

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments t…

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments t…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-73037Medium· 6.1
1mo ago

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitra…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-18741Medium· 4.8PoC
1mo ago

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inject arbitrary JavaScript by entering malicious payloads into the L…

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inject arbitrary JavaScript by entering malicious payloads into the L…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-73628Medium· 6.1
1mo ago

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>)

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecod…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-3639Medium· 6.4
1mo ago

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and outp…

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and outp…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-73572Medium· 6.1
1mo ago

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker ca…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-56858High· 8.1
1mo ago

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

▾ Twilightstdlib · stdlibEPSS 0.31%via OSV
CVE-2026-73417High· 8.3
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an ov…

▾ Twilightjupyterlab · jupyterlabEPSS 0.75%via NVD
CVE-2026-49864High
1mo ago

wetty provides terminal access in browser over http/https

wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: fals…

▾ Twilightwetty · wettyEPSS 0.44%via NVD
CVE-2026-57858High· 8.9PoC
1mo ago

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…

▾ MidnightEPSS 0.37%via NVD
CWE-79 vulnerabilities (CVEs) — page 36 · VulnSea