VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

CVE-2026-70332Critical· 9.6
1mo ago

Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft SharePoint OnlineEPSS 0.86%via CVEORG
CVE-2026-66707High· 7.1
1mo ago

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-66664High· 7.1
1mo ago

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-71497Medium· 4.7
1mo ago

jsoup is a Java library for working with real-world HTML

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…

▾ Sunlitjsoup · org.jsoup:jsoupEPSS 0.30%via NVD
CVE-2026-16633High
1mo ago

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

▾ Twilightpdfjs-dist · pdfjs-distvia GHSA
GHSA-2rp4-x2j7-qmccMedium
1mo ago

Craft CMS: Stored XSS in the control panel via unescaped draft name

Craft CMS: Stored XSS in the control panel via unescaped draft name

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-54717Medium· 5.4
1mo ago

Silverstripe CMS is an open source content management system

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb t…

▾ Sunlitsilverstripe · silverstripe/cmsEPSS 0.34%via NVD
CVE-2026-71478Medium· 6.1
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…

▾ Sunlitleague · league/commonmarkEPSS 0.36%via NVD
CVE-2026-71435Medium· 6.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-53992Medium· 6.1
1mo ago

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GE…

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GE…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-9195Critical· 9.3
1mo ago

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the adm…

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the adm…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-71236High· 8.7
1mo ago

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &…

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-71233High· 8.7
1mo ago

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitiza…

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitiza…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-70596Medium· 4.3
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …

▾ Sunlitghost · ghostEPSS 0.32%via NVD
CVE-2026-10032Medium· 6.1
1mo ago

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall ac…

▾ Sunlitgoogle · a2ui/web_coreEPSS 0.13%via NVD
CVE-2026-67196Medium· 5.4
1mo ago

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpola…

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpola…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-52370Medium· 6.1
1mo ago

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-65986None
1mo ago

CVAT is an open source interactive video and image annotation tool for computer vision

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached t…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-14337None
1mo ago

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

▾ SunlitEPSS 0.42%via NVD
CVE-2026-53950High· 7.5
1mo ago

XSS in Ghost's ActivityPub client

XSS in Ghost's ActivityPub client

▾ Twilighttryghost · @tryghost/activitypubEPSS 0.35%via GHSA
CVE-2026-70492High· 8.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes K…

▾ Twilightopenwebui · open_webuiEPSS 0.40%via NVD
CVE-2026-70588Medium· 5.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

▾ Sunlitghost · ghostEPSS 0.43%via NVD
CVE-2026-70486High· 8.2
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-49132Medium· 5.4
1mo ago

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate A…

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate A…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-49131Medium· 5.4
1mo ago

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule de…

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule de…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-67617Medium· 4.8
1mo ago

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names …

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names …

▾ SunlitEPSS 0.27%via NVD
CVE-2026-67612Medium· 4.8
1mo ago

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the t…

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the t…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-69092Medium· 6.5
1mo ago

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript throu…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-69149High
1mo ago

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

▾ Twilightangular · @angular/platform-serverEPSS 0.35%via GHSA
CVE-2026-69151High
1mo ago

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

▾ Twilightangular · @angular/compilerEPSS 0.33%via GHSA
CWE-79 vulnerabilities (CVEs) — page 39 · VulnSea