VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-15731Medium· 6.4
3d ago

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output …

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output …

▾ Sunlitmagazine3 · WP Multilang – Translation and Multilingual PluginEPSS 0.25%via NVD
CVE-2026-11744Low· 3.8
3d ago

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's we…

▾ SunlitPaperCut · PaperCut HiveEPSS 0.17%via NVD
CVE-2026-89005Medium· 6.8
3d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stor…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stor…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-89002Medium· 6.8
3d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-84151Low· 3.5
3d ago

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-96810Low· 3.5PoC
3d ago

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonCont…

▾ Twilighthuanzi-qch · base-adminEPSS 0.19%via NVD
CVE-2026-96739Medium· 4.3PoC
3d ago

A flaw has been found in SEMCMS up to 4.2

A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross si…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-66077High· 7.3
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-84683High· 8.7
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal es…

▾ TwilightRed Hat · automation-controllerEPSS 0.26%via NVD
CVE-2026-77394High· 7.6PoC
4d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /ope…

▾ MidnightOpenC3 · cosmosEPSS 0.39%via NVD
CVE-2026-92730High· 7.4
4d ago

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

▾ TwilightLimeSurvey · LimeSurveyEPSS 0.39%via NVD
CVE-2026-93526High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

▾ TwilightNexcess · event-ticketsEPSS 0.18%via NVD
CVE-2026-93622High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

▾ TwilightNicolasKulka · wps-limit-loginEPSS 0.18%via NVD
CVE-2026-93772Medium· 6.5
4d ago

Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.

Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.

▾ SunlitTomdever · wpforoEPSS 0.22%via NVD
CVE-2026-93774High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

▾ TwilightJacob N. Breetvelt · wp-photo-album-plusEPSS 0.19%via NVD
CVE-2026-94118Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

▾ SunlitLeap13 · premium-blocks-for-gutenbergEPSS 0.17%via NVD
CVE-2026-94168Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

▾ SunlitLeap13 · premium-addons-for-elementorEPSS 0.17%via NVD
CVE-2026-94176High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

▾ TwilightKitae Park · mangboardEPSS 0.19%via NVD
CVE-2026-94179High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.

Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.

▾ TwilightRazorpay · razorpay-payment-buttonEPSS 0.19%via NVD
CVE-2026-94461Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

▾ Sunlitmetaphorcreations · ditty-news-tickerEPSS 0.17%via NVD
CVE-2026-94391Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

▾ SunlitRustaurius · ultimate-faqsEPSS 0.17%via NVD
CVE-2026-94500Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.

Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.

▾ SunlitRoxnor · elementskit-liteEPSS 0.17%via NVD
CVE-2026-94671Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

▾ SunlitRadiusTheme · the-post-gridEPSS 0.17%via NVD
CVE-2026-94680Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

▾ SunlitRadiusTheme · the-post-gridEPSS 0.17%via NVD
CVE-2026-94684Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.

Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.

▾ Sunlitoceanwp · ocean-extraEPSS 0.17%via NVD
CVE-2026-94682Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.

Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.

▾ SunlitSecondLineThemes · podcast-importer-secondlineEPSS 0.17%via NVD
CVE-2026-95515High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

▾ TwilightKevin Stover · ninja-formsEPSS 0.18%via NVD
CVE-2026-95530Medium· 6.5
4d ago

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

▾ SunlitPixelYourSite · pixelyoursiteEPSS 0.21%via NVD
CVE-2026-95529High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

▾ Twilightcodepeople · calculated-fields-formEPSS 0.18%via NVD
CVE-2026-95528High· 7.1
4d ago

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

▾ TwilightMohammed Kaludi · core-web-vitals-pagespeed-boosterEPSS 0.18%via NVD
CWE-79 vulnerabilities (CVEs) — page 5 · VulnSea