VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2125 CVEsRSS

GHSA-9wjq-cp2p-hrgfMedium· 4.7
2mo ago

Loofah: SVG `href` attribute bypasses local-reference restriction

Loofah: SVG `href` attribute bypasses local-reference restriction

▾ Sunlitloofah · loofahvia GHSA
GHSA-5qhf-9phg-95m2Low
2mo ago

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

▾ Sunlitloofah · loofahvia GHSA
GHSA-cj75-f6xr-r4g7Medium
2mo ago

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

▾ Sunlitrails-html-sanitizer · rails-html-sanitizervia GHSA
GHSA-c2j3-45gr-mqc4Low
2mo ago

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-2p49-hgcm-8545High· 8.2
2mo ago

SVGO removeScripts plugin leaves some executable scripts intact

SVGO removeScripts plugin leaves some executable scripts intact

▾ Twilightsvgo · svgovia GHSA
CVE-2026-59895Medium· 6.1
2mo ago

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

▾ Sunlithono · honoEPSS 0.33%via GHSA
CVE-2026-39878Critical· 9.3
2mo ago

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, le…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-35198Critical· 9.0
2mo ago

HeyForm is an open-source form builder

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-44230Medium· 6.1
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an att…

▾ Sunlitbestpractical · request_trackerEPSS 0.26%via NVD
CVE-2026-44228Medium· 5.4
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML esca…

▾ Sunlitbestpractical · request_trackerEPSS 0.26%via NVD
CVE-2026-44227Medium· 6.1
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit …

▾ Sunlitbestpractical · request_trackerEPSS 0.26%via NVD
CVE-2026-59727Low
2mo ago

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

▾ Sunlitastro · astroEPSS 0.54%via GHSA
CVE-2026-59729Medium
2mo ago

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

▾ Sunlitastro · astroEPSS 0.54%via GHSA
GHSA-4g3v-8h47-v7g6Medium
2mo ago

Astro: Reflected XSS via unescaped View Transition animation properties

Astro: Reflected XSS via unescaped View Transition animation properties

▾ Sunlitastro · astrovia GHSA
CVE-2026-16229Medium· 4.3
2mo ago

A flaw has been found in itsourcecode Courier Management System up to 1.0

A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting.…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-16220Medium· 4.3
2mo ago

A vulnerability has been found in code-projects Online Examination System 1.0

A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack c…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-16205Low· 2.4
2mo ago

A weakness has been identified in Pluck CMS up to 4.7.21

A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the ar…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-16203Low· 3.5
2mo ago

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting.…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-16202Low· 3.5
2mo ago

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-16156Low· 3.5
2mo ago

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to l…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-57857Medium· 4.3
2mo ago

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed dire…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-16155Low· 3.5
2mo ago

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-12228High· 8.7
2mo ago

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version)

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without serve…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-62826Medium· 4.6
2mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-58643Medium· 6.1
2mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Windows Admin CenterEPSS 0.41%via NVD
CVE-2026-45368None
2mo ago

Kirby is an open-source content management system

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. T…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-63081Medium· 5.4
2mo ago

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of …

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of …

▾ SunlitEPSS 0.24%via NVD
CVE-2026-13042High· 7.2
2mo ago

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for u…

▾ TwilightEPSS 0.43%via NVD
GHSA-373m-p57p-8665Medium· 6.1
2mo ago

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-45738High· 7.3
2mo ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rende…

▾ Twilightargoproj · argo_cdEPSS 0.61%via NVD
CWE-79 vulnerabilities (CVEs) — page 42 · VulnSea