VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-70560Medium· 5.4
1mo ago

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user…

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-73492None
1mo ago

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose sch…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-73490Medium· 4.7
1mo ago

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute …

▾ SunlitEPSS 0.30%via NVD
CVE-2026-73427None
1mo ago

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallbac…

▾ SunlitEPSS 0.57%via NVD
CVE-2026-49466Medium· 6.5
1mo ago

Draft List is a WordPress plugin to manage and promote unpublished content

Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List widget when the documented custom `templa…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-48552Medium· 5.4
1mo ago

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-48550Medium· 6.1
1mo ago

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an auth…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-73262Medium· 5.4
1mo ago

Prowler is a cloud security platform

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTM…

▾ Sunlitprowler · prowlerEPSS 0.30%via NVD
CVE-2026-73295Medium· 5.4
1mo ago

Material for MkDocs is a powerful documentation framework built on top of MkDocs

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-s…

▾ Sunlitmkdocs-material · mkdocs-materialEPSS 0.33%via NVD
CVE-2026-65937High· 8.0
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

▾ TwilightEPSS 0.41%via NVD
CVE-2026-73422None
1mo ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML context…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-73415High· 8.0
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.74%via NVD
CVE-2026-9318Medium· 5.4
1mo ago

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

▾ Sunlittablib · tablibEPSS 0.30%via NVD
CVE-2026-48414High· 7.7
1mo ago

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's…

▾ Twilightadobe · commerceEPSS 0.33%via NVD
CVE-2026-48413High· 8.7
1mo ago

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's…

▾ Twilightadobe · commerceEPSS 0.70%via NVD
CVE-2026-73031High· 8.7
1mo ago

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. Th…

▾ TwilightEPSS 0.66%via NVD
CVE-2026-73084Medium· 6.1
1mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A craf…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-72747High· 7.2
1mo ago

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phon…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-21269Medium· 4.6
1mo ago

ColdFusion is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

ColdFusion is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's bro…

▾ Sunlitadobe · coldfusionEPSS 0.50%via NVD
CVE-2026-70355High· 7.3
1mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server 2019EPSS 0.78%via CVEORG
CVE-2026-70306Critical· 9.3
1mo ago

Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 1.0%via CVEORG
CVE-2026-72925Medium· 6.1
1mo ago

SWC is a TypeScript / JavaScript compiler written in Rust

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-contro…

▾ Sunlitswc · @swc/htmlEPSS 0.34%via NVD
CVE-2026-62829Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Server 2019EPSS 0.47%via CVEORG
CVE-2026-57105High· 8.0
1mo ago

Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server 2019EPSS 0.62%via CVEORG
CVE-2026-64922Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-62914High· 7.3
1mo ago

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.45%via CVEORG
CVE-2026-64902Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-64897Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-64916Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-64900High· 7.3
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.65%via CVEORG
CWE-79 vulnerabilities (CVEs) — page 37 · VulnSea