VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2141 CVEsRSS

CVE-2026-34801Medium· 6.4
5mo ago

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other use…

▾ Sunlitendian · firewall_communityEPSS 0.24%via NVD
CVE-2026-34800Medium· 6.4
5mo ago

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users …

▾ Sunlitendian · firewall_communityEPSS 0.24%via NVD
CVE-2026-34799Medium· 6.4
5mo ago

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users v…

▾ Sunlitendian · firewall_communityEPSS 0.24%via NVD
CVE-2026-34798Medium· 6.4
5mo ago

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users vie…

▾ Sunlitendian · firewall_communityEPSS 0.24%via NVD
CVE-2026-2737Medium· 6.1
5mo ago

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…

▾ Sunlitprogress · flowmonEPSS 0.25%via NVD
CVE-2026-20090Medium· 4.8
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.24%via NVD
CVE-2026-20089Medium· 4.8
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.24%via NVD
CVE-2026-20088Medium· 4.8
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.22%via NVD
CVE-2026-20087Medium· 4.8
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.17%via NVD
CVE-2026-20085Medium· 6.1
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation…

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.18%via NVD
CVE-2026-34448Critical· 9.0
6mo ago

SiYuan is a personal knowledge management system

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -…

▾ Midnightb3log · siyuanEPSS 0.73%via NVD
CVE-2026-34405Medium· 6.1
6mo ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary att…

▾ Sunlitnuxt · og_imageEPSS 0.26%via NVD
CVE-2026-20915Medium· 5.4
6mo ago

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in …

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in …

▾ Sunlitcheckmk · checkmkEPSS 0.15%via NVD
CVE-2026-33276Medium· 5.4
6mo ago

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Uni…

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Uni…

▾ Sunlitcheckmk · checkmkEPSS 0.23%via NVD
CVE-2026-32607Medium· 5.4
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is ena…

▾ Sunlitdiscourse · discourseEPSS 0.28%via NVD
CVE-2026-32273Medium· 5.4
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the …

▾ Sunlitdiscourse · discourseEPSS 0.28%via NVD
CVE-2026-32243Medium· 5.4
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations…

▾ Sunlitdiscourse · discourseEPSS 0.29%via NVD
CVE-2025-62184Low· 3.4
6mo ago

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low a…

▾ Sunlitpega · pega_platformEPSS 0.26%via NVD
CVE-2026-4267High· 7.2
6mo ago

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and including, 3.20.3 due to insufficient…

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and including, 3.20.3 due to insufficient…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-3457Medium· 6.8
6mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22.

▾ SunlitEPSS 0.18%via NVD
CVE-2026-33941High· 8.2PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…

▾ Midnighthandlebarsjs · handlebarsEPSS 0.22%via NVD
CVE-2026-20112Medium· 4.8
6mo ago

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o…

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.19%via NVD
CVE-2026-24370Medium· 6.5
6mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeOne The Grid allows Stored XSS. This issue affects The Grid: from n/a through 2.8.0.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeOne The Grid allows Stored XSS. This issue affects The Grid: from n/a through 2.8.0.

▾ SunlitEPSS 0.21%via NVD
CVE-2026-2072High· 8.2
6mo ago

Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.…

Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.…

▾ Twilighthitachi · infrastructure_analytics_advisorEPSS 0.16%via NVD
CVE-2026-20108Medium· 5.4
6mo ago

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. …

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. …

▾ Sunlitcisco · catalyst_sd-wan_managerEPSS 0.16%via NVD
CVE-2026-33167Medium· 6.1
6mo ago

Action Pack is a Rubygem for building web applications on the Rails framework

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message c…

▾ Sunlitrubyonrails · railsEPSS 0.33%via NVD
CVE-2026-31938Critical· 9.6
6mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created P…

▾ Midnightparall · jspdfEPSS 0.40%via NVD
CVE-2026-56397Medium
6mo ago

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via GHSA
CVE-2026-2514Medium· 6.1
6mo ago

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

▾ Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.18%via NVD
CVE-2026-2513Medium· 6.1
6mo ago

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

▾ Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.16%via NVD
CWE-79 vulnerabilities (CVEs) — page 55 · VulnSea