VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2126 CVEsRSS

CVE-2026-50229Medium· 6.1PoC
3mo ago

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

▾ Twilightapache · tomcatEPSS 4.1%via NVD
CVE-2026-13536Medium· 4.3
3mo ago

A vulnerability has been found in GotoHTTP up to 10.2

A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-13504Low· 3.5
3mo ago

A vulnerability has been found in code-projects Project Management System 1.0

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-13499Medium· 4.3
3mo ago

A security flaw has been discovered in yashpokharna2555 restaurent-management-system

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Userna…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-57322High· 7.1
3mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2.

▾ TwilightweDevs · wemailEPSS 0.25%via NVD
CVE-2026-52781Medium· 6.4
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricted data-* attributes via :data wildcard. An attacker injects data-controller="poll-for-ch…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-48788High· 8.2
3mo ago

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing

▾ Twilightumputun · github.com/umputun/remark42EPSS 0.41%via GHSA
GHSA-75mw-h36v-2jv7Medium· 6.1
3mo ago

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

▾ Sunlitdosage · dosagevia GHSA
CVE-2026-48942Medium· 6.1
3mo ago

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-48940Low· 3.4
3mo ago

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

▾ SunlitEPSS 0.28%via NVD
GHSA-jf6w-2mvx-633jMedium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlvia GHSA
CVE-2026-11998High· 7.6
3mo ago

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to …

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to …

▾ TwilightEPSS 0.50%via NVD
CVE-2026-56785High· 8.2
3mo ago

FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields

FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaSc…

▾ TwilightFlatPress · FlatPressEPSS 0.42%via CVEORG
CVE-2026-52807High
3mo ago

Gogs has DOM-based XSS via Milestone Name on New Issue Page

Gogs has DOM-based XSS via Milestone Name on New Issue Page

▾ Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
CVE-2026-52816Medium
3mo ago

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

▾ Sunlitgogs · gogs.io/gogsEPSS 0.68%via GHSA
GHSA-7cqp-7cfv-6c3qMedium
3mo ago

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

▾ Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-48157Medium· 6.1
3mo ago

Slim has Reflected XSS in the HtmlErrorRenderer

Slim has Reflected XSS in the HtmlErrorRenderer

▾ Sunlitslim · slim/slimEPSS 0.26%via GHSA
CVE-2026-48167Medium· 6.4
3mo ago

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

▾ Sunlitfilament · filament/infolistsEPSS 0.25%via GHSA
CVE-2023-45796High· 8.1
3mo ago

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potenti…

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potenti…

▾ TwilightEPSS 0.63%via NVD
CVE-2023-45795High· 7.8
3mo ago

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

▾ TwilightEPSS 0.21%via NVD
CVE-2026-9029High· 7.3
3mo ago

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…

▾ Twilightgrafana · grafanaEPSS 0.32%via NVD
CVE-2026-50556Medium· 6.1
3mo ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in…

▾ Sunlitangularjs · angularjsEPSS 0.41%via NVD
GHSA-hvqh-jw65-wcpqMedium· 5.4
3mo ago

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

▾ Sunlitdevbridge-autocomplete · devbridge-autocompletevia GHSA
CVE-2026-52798High· 8.9
3mo ago

Gogs has Stored XSS in `.ipynb` Preview

Gogs has Stored XSS in `.ipynb` Preview

▾ Twilightgogs · gogs.io/gogsEPSS 0.43%via GHSA
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-xppm-jmw6-fhmfLow
3mo ago

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-32208High· 8.8
3mo ago

Microsoft Entra ID Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.52%via CVEORG
CVE-2026-12048Critical· 9.3
3mo ago

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside E…

▾ Midnightpgadmin · pgadmin_4EPSS 0.27%via NVD
CVE-2026-12047Low· 3.5
3mo ago

HTML injection in pgAdmin 4's cloud deployment module

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception…

▾ Sunlitpgadmin · pgadmin_4EPSS 0.22%via NVD
GHSA-q76j-gcg9-vxc6Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
CWE-79 vulnerabilities (CVEs) — page 47 · VulnSea