VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2126 CVEsRSS

CVE-2026-49978High· 8.1
2mo ago

dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)

A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM eleme…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.40%via CSAF
CVE-2026-4765None· 0.0
2mo ago

Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature

Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation …

▾ SunlitRD Station Conversas · Tallos ChatEPSS 0.44%via NVD
CVE-2026-54064High· 8.7
2mo ago

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2024-27091Medium· 6.1
2mo ago

GeoNode: Stored XSS to full account takeover

GeoNode: Stored XSS to full account takeover

▾ Sunlitgeonode · geonodeEPSS 0.38%via GHSA
CVE-2026-48118High· 8.2
2mo ago

NukeViet: Unauthenticated Reflected XSS in Comment Module

NukeViet: Unauthenticated Reflected XSS in Comment Module

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-49259High· 8.7
2mo ago

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-57829NonePoC
2mo ago

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-15532Low· 2.4
2mo ago

A vulnerability was identified in SourceCodester Online Book Store System 1.0

A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site script…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-15552Medium· 6.1
2mo ago

Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.

Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.

▾ SunlitEPSS 0.34%via NVD
CVE-2026-15505Low· 3.5
2mo ago

A weakness has been identified in vnotex vnote up to 3.20.1

A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross si…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-61876High· 8.8PoC
2mo ago

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-61875High· 8.8
2mo ago

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-15493Low· 3.5
2mo ago

A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee

A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15492Medium· 4.3
2mo ago

A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6

A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulnerability affects unknown code of the file dashboard/studentConductManager.php. Such manipulation leads to cross site …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-6939High· 7.2
2mo ago

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output e…

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output e…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-1382Medium· 6.4
2mo ago

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user suppl…

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user suppl…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15010Medium· 6.4
2mo ago

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-12126Medium· 6.4
2mo ago

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitizati…

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitizati…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-11898Medium· 4.4
2mo ago

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for …

▾ SunlitEPSS 0.40%via NVD
CVE-2026-11591Medium· 4.4
2mo ago

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it poss…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-13378High· 7.2
2mo ago

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output esc…

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output esc…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-9738Medium· 4.4
2mo ago

The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and out…

The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and out…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-15097Medium· 6.4
2mo ago

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This ma…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15096Medium· 6.4
2mo ago

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes i…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-12141Medium· 4.9
2mo ago

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to ins…

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to ins…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-13968Medium· 6.4
2mo ago

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insuffici…

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insuffici…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-5743Medium· 6.4
2mo ago

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-3367Medium· 4.4
2mo ago

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output es…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-13114High· 7.2
2mo ago

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient i…

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient i…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-58591None
2mo ago

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

▾ SunlitEPSS 0.23%via NVD
CWE-79 vulnerabilities (CVEs) — page 44 · VulnSea