VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-66805High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-57104High· 8.8
1mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Storage ExplorerEPSS 0.86%via NVD
CVE-2026-65767High· 8.8
1mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · teamsEPSS 0.61%via NVD
CVE-2026-72743Medium· 5.4
1mo ago

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text w…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-69116Medium· 6.1PoC
1mo ago

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron render…

▾ Twilightxpf0000 · FlyEnvEPSS 0.34%via NVD
CVE-2026-44401Medium· 4.8PoC
1mo ago

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitiz…

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitiz…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-63105Medium· 5.4
1mo ago

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized …

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized …

▾ SunlitEPSS 0.24%via NVD
CVE-2026-72730High· 8.7
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-72729None
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content S…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-72727None
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a modera…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-72725Medium· 5.4
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-72720Medium· 6.4
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute values are reparsed as markup. Crafted Vi…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-72594High· 7.6
1mo ago

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

▾ TwilightEPSS 0.28%via NVD
CVE-2026-72583Medium· 5.4
1mo ago

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME type allow-list check.

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME type allow-list check.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-72576Medium· 5.4
1mo ago

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the S…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-19378Medium· 4.3
1mo ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in …

▾ SunlitEPSS 0.47%via NVD
CVE-2026-71502None
1mo ago

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…

▾ SunlitEPSS 0.74%via NVD
CVE-2026-18988Medium· 6.4
1mo ago

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-17596Medium· 6.1
1mo ago

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS)

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which woul…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.24%via NVD
CVE-2026-48094None
1mo ago

The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content

The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-48026High· 8.7
1mo ago

lakeFS is an open-source tool that transforms object storage into a Git-like repositories

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository obje…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-62293Medium· 5.0
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source re…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-48093Medium· 6.5
1mo ago

The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content

The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches th…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-19207Low· 2.4
1mo ago

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-66494None
1mo ago

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an adm…

▾ SunlitEPSS 0.50%via NVD
GHSA-55q2-fjhq-7xh7Medium
1mo ago

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-66457High· 7.1
1mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.

▾ TwilightPixelite · events-managerEPSS 0.25%via NVD
CVE-2026-49391None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-48081High· 8.1
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `p…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-47185None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user…

▾ SunlitEPSS 0.41%via NVD
CWE-79 vulnerabilities (CVEs) — page 38 · VulnSea