CWE-79
CVEs classified under CWE-79, newest first.
2126 CVEsRSS
CVE-2026-50133MediumHugo: XSS via text/html content files
Hugo: XSS via text/html content files
CVE-2026-56266Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302High· 7.6n8n: Stored XSS in Chat Trigger Node
n8n: Stored XSS in Chat Trigger Node
GHSA-m3q2-p4fw-w38mLowCross-site scripting via <NoScript> slot content in Nuxt's head components
Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-54326Low· 2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-54267HighAngular Client Hydration DOM Clobbering & Response-Cache Poisoning
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
CVE-2026-48761MediumSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
CVE-2026-52725Medium@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
CVE-2026-50555High@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-50557MediumAngular: Template and Attribute Namespace Sanitization Bypass (XSS)
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
CVE-2026-54265Medium@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
CVE-2026-49459Medium· 6.1DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-49458Medium· 6.1DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
GHSA-x4vx-rjvf-j5p4LowDOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
GHSA-gvmj-g25r-r7wrLowDOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
CVE-2026-9125Medium· 6.4The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitizat…
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitizat…
CVE-2026-44990Critical· 9.3PoCApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…
GHSA-6jq6-x4cx-qvcmMediumFirefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
CVE-2026-47344LowTYPO3 HTML Sanitizer allows Cross-site Scripting
TYPO3 HTML Sanitizer allows Cross-site Scripting
CVE-2026-47348MediumTYPO3 CMS has Cross-Site Scripting in Indexed Search
TYPO3 CMS has Cross-Site Scripting in Indexed Search
CVE-2026-47345MediumTYPO3 HTML Sanitizer allows Cross-site Scripting
TYPO3 HTML Sanitizer allows Cross-site Scripting
CVE-2026-44311Medium· 5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
CVE-2026-40986Medium· 4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server cont…
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server cont…
CVE-2026-41003High· 7.6An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 …
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 …
CVE-2026-0266Medium· 4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-…
CVE-2026-48060High· 8.1PoCLitestar has HTML Injection Through its CSRF Token
Litestar has HTML Injection Through its CSRF Token
CVE-2026-53441Medium· 5.4Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a store…
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a store…
CVE-2026-45468Medium· 4.6Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-45467Medium· 4.6Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.