VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-96039High· 7.2
2d ago

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it poss…

▾ Twilightbookingalgorithms · BA Book EverythingEPSS 0.24%via NVD
CVE-2026-92746Medium· 6.4
2d ago

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient…

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient…

▾ Sunlitjegstudio · Gutenverse – WordPress Blocks, Page Builder & Site EditorEPSS 0.19%via NVD
CVE-2025-14814Medium· 6.4
2d ago

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping o…

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping o…

▾ Sunlitwipeoutmedia · CSS & JavaScript ToolboxEPSS 0.16%via NVD
CVE-2026-97735High· 8.0
2d ago

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

▾ TwilightITFlow · ITFlowEPSS 0.25%via NVD
CVE-2026-97650Medium· 4.3
2d ago

A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation of the argument reason/…

▾ Sunlitningzichun · student-management-systemEPSS 0.27%via NVD
CVE-2026-97723Medium· 5.4
2d ago

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML l…

▾ Sunlitmadpsy · ka9q_ubersdrEPSS 0.21%via NVD
CVE-2026-48542Medium· 5.4
3d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-48543Medium· 5.4PoC
3d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

▾ Twilightkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-48541Medium· 5.4
3d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-48540Medium· 5.4PoC
3d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

▾ Twilightkrayin · laravel-crmEPSS 0.17%via NVD
CVE-2026-57439Medium· 5.0
3d ago

CyberChef: Prototype pollution in Series Chart operation

CyberChef: Prototype pollution in Series Chart operation

▾ Sunlitcyberchef · cyberchefEPSS 0.24%via GHSA
CVE-2026-97322Medium· 4.3
3d ago

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the c…

▾ SunlitYunaiV · ruoyi-vue-proEPSS 0.26%via NVD
CVE-2026-57440High· 7.5
3d ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (n…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.26%via NVD
CVE-2026-61825High· 8.7
3d ago

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content be…

▾ Twilightcode16 · sharpEPSS 0.22%via NVD
CVE-2026-61823High· 7.3
3d ago

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permit…

▾ Twilightcode16 · sharpEPSS 0.21%via NVD
CVE-2026-93405Medium· 6.1
3d ago

Mailspring is a fast, cross-platform, open-source email client

Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview …

▾ SunlitFoundry376 · MailspringEPSS 0.22%via NVD
CVE-2026-91119Medium· 6.4
3d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attri…

▾ Sunlitdiscourse · discourseEPSS 0.20%via NVD
CVE-2026-91120Medium· 5.4
3d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat su…

▾ Sunlitdiscourse · discourseEPSS 0.20%via NVD
CVE-2026-61784Medium· 6.1
3d ago

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeS…

▾ Sunlitxhtml-purifier · xhtml-purifierEPSS 0.17%via NVD
CVE-2026-91121Medium· 5.0
3d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and se…

▾ Sunlitdiscourse · discourseEPSS 0.26%via NVD
CVE-2026-97233Low· 3.5
3d ago

A vulnerability was identified in volotat Anagnorisis up to 0.4.11

A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to …

▾ Sunlitvolotat · AnagnorisisEPSS 0.19%via NVD
CVE-2026-91122High· 8.7
3d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An…

▾ Twilightdiscourse · discourseEPSS 0.26%via NVD
CVE-2026-63498High· 8.7
3d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments…

▾ Twilightgrokability · snipe-itEPSS 0.24%via NVD
CVE-2026-62368High· 8.1PoC
3d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-ta…

▾ Midnightsnipe · snipe/snipe-itEPSS 0.30%via NVD
CVE-2026-96873Medium· 5.5
3d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.

▾ SunlitThe Wikimedia Foundation · Mediawiki - CirrusSearch ExtensionEPSS 0.27%via NVD
CVE-2026-97224Medium· 4.3
3d ago

A vulnerability was detected in Excalidraw up to 0.18.1

A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File Handler. Performing a manipulation of the argument custom…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-56736High· 8.2PoC
3d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that ex…

▾ Midnightthorsten · phpMyFAQEPSS 0.24%via NVD
CVE-2026-12559High· 7.3
3d ago

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized scri…

▾ TwilightOpenText · Vendor Invoice Management for SAP SolutionsEPSS 0.39%via NVD
CVE-2026-97062Medium· 5.4PoC
3d ago

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with scrip…

▾ TwilightWebkul · Aureus ERPEPSS 0.22%via NVD
CVE-2026-4637Medium· 5.1PoC
3d ago

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 …

▾ TwilightPaessler GmbH · PRTG Network MonitorEPSS 0.55%via NVD
CWE-79 vulnerabilities (CVEs) — page 4 · VulnSea