CWE-79
CVEs classified under CWE-79, newest first.
2126 CVEsRSS
GHSA-4wj4-79rr-pvffMedium· 4.8Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
CVE-2026-12948NonePoCA stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system c…
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system c…
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
CVE-2025-46571MediumOpen WebUI allows limited stored XSS vila uploaded html file
Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46719HighOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
CVE-2026-26192High· 7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26193High· 7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-55437Medium· 5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
CVE-2026-55790HighCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
CVE-2026-55793MediumCraft CMS: Stored XSS via Structure entry title in table view
Craft CMS: Stored XSS via Structure entry title in table view
CVE-2026-57977High· 7.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58298High· 7.2Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58524Medium· 5.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-4322Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS. This issue affects Destekz: through 02062026. N…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS. This issue affects Destekz: through 02062026. N…
CVE-2026-9756Medium· 6.4The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and out…
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and out…
CVE-2026-4804Medium· 6.4The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0
The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is due to the theme registering three post meta fields (zakra_menu_item_color, zakra_menu_i…
CVE-2026-9148High· 7.2The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAutho…
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAutho…
CVE-2026-8351Medium· 6.4The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'backgr…
The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'backgr…
CVE-2026-9626Medium· 6.4The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in th…
The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in th…
CVE-2026-8892Medium· 6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input san…
The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input san…
CVE-2026-8489Medium· 6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and …
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and …
CVE-2026-13040High· 7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and o…
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and o…
CVE-2026-13374NoneImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmiti…
CVE-2026-9809High· 7.6PoCMautic has Stored Cross-Site Scripting (XSS) in Projects Component
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
CVE-2026-9811Medium· 5.4PoCMautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
CVE-2026-50290Medium@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
GHSA-hwmc-r6mf-jh83LowSchema.org has cross-site scripting (XSS) via script break-out in toScript() output
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
GeoNetwork has reflected XSS through client-side template injection
CVE-2026-56809Medium· 6.1Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a c…