CWE-79
CVEs classified under CWE-79, newest first.
2125 CVEsRSS
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
GHSA-cj75-f6xr-r4g7MediumRails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-c2j3-45gr-mqc4LowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
GHSA-2p49-hgcm-8545High· 8.2SVGO removeScripts plugin leaves some executable scripts intact
SVGO removeScripts plugin leaves some executable scripts intact
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-39878Critical· 9.3Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…
CVE-2026-35198Critical· 9.0HeyForm is an open-source form builder
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner…
CVE-2026-44230Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an att…
CVE-2026-44228Medium· 5.4RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML esca…
CVE-2026-44227Medium· 6.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit …
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-59729MediumAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-4g3v-8h47-v7g6MediumAstro: Reflected XSS via unescaped View Transition animation properties
Astro: Reflected XSS via unescaped View Transition animation properties
CVE-2026-16229Medium· 4.3A flaw has been found in itsourcecode Courier Management System up to 1.0
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting.…
CVE-2026-16220Medium· 4.3A vulnerability has been found in code-projects Online Examination System 1.0
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack c…
CVE-2026-16205Low· 2.4A weakness has been identified in Pluck CMS up to 4.7.21
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the ar…
CVE-2026-16203Low· 3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting.…
CVE-2026-16202Low· 3.5A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting…
CVE-2026-16156Low· 3.5A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to l…
CVE-2026-57857Medium· 4.3The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page
The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed dire…
CVE-2026-16155Low· 3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It…
CVE-2026-12228High· 8.7A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version)
A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without serve…
CVE-2026-62826Medium· 4.6Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-58643Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45368NoneKirby is an open-source content management system
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. T…
CVE-2026-63081Medium· 5.4Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of …
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of …
CVE-2026-13042High· 7.2The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for u…
GHSA-373m-p57p-8665Medium· 6.1Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
CVE-2026-45738High· 7.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rende…