CWE-79
CVEs classified under CWE-79, newest first.
2126 CVEsRSS
CVE-2026-49210Mediumsymfony/ux-live-component: XSS via attacker-controlled child component tag
symfony/ux-live-component: XSS via attacker-controlled child component tag
CVE-2026-49216Mediumsymfony/ux-autocomplete: XSS via unescaped AJAX response data
symfony/ux-autocomplete: XSS via unescaped AJAX response data
CVE-2026-53724Lowparse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
CVE-2026-54527Highjupyterlab-git extension: Stored XSS leading to RCE
jupyterlab-git extension: Stored XSS leading to RCE
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
CVE-2026-55877Medium· 6.1symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
GHSA-h5jc-78hr-3pc9LowSveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
GHSA-x975-rgx4-5fh4High· 8.2appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
CVE-2026-54386Medium· 6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
marimo contains a reflected cross-site scripting vulnerability in the notebook page
CVE-2026-55746High· 7.6Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
CVE-2026-55661MediumTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
GHSA-63v4-w882-g4x2High· 8.8PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
GHSA-cmwh-pvxp-8882MediumDOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
CVE-2026-55890Medium· 4.8Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
CVE-2026-44727Medium· 5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-54002HighKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
CVE-2026-53841Medium· 6.1OpenClaw: Exported session HTML could keep unsafe markdown links
OpenClaw: Exported session HTML could keep unsafe markdown links
CVE-2026-53929MediumNocoDB: Stored Cross-Site Scripting via Secure Attachment
NocoDB: Stored Cross-Site Scripting via Secure Attachment
CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-54013High· 7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-28737High· 8.7Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
CVE-2026-48591Mediumearmark: Stored XSS via unescaped HTML attribute values
earmark: Stored XSS via unescaped HTML attribute values
CVE-2026-55409High· 7.6Filament: Disabled RichEditor field state can be used for XSS
Filament: Disabled RichEditor field state can be used for XSS
CVE-2026-56317LowCross-site scripting via <NoScript> slot content in Nuxt's head components
Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-56326Medium· 6.1Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-53722MediumNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
CVE-2026-50146High· 7.1Astro: Reflected XSS via unescaped slot name
Astro: Reflected XSS via unescaped slot name
GHSA-gj48-438w-jh9vMedium· 6.1Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
CVE-2026-54298Medium· 4.2Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: XSS via Unescaped Attribute Names in Spread Props
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node