VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2141 CVEsRSS

CVE-2026-20117Medium· 6.1
6mo ago

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. …

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. …

▾ Sunlitcisco · unified_contact_center_expressEPSS 0.21%via NVD
CVE-2025-13902Medium· 5.4
6mo ago

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victi…

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victi…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-29052Medium· 6.1
6mo ago

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability …

▾ Sunlithumhub · calendarEPSS 0.26%via NVD
CVE-2025-66024Critical· 9.0PoC
6mo ago

The XWiki blog application allows users of the XWiki platform to create and manage blog posts

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…

▾ Abyssalxwiki · blog_applicationEPSS 0.36%via NVD
CVE-2026-3343Medium· 6.1
6mo ago

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

▾ Sunlitwatchguard · firewareEPSS 0.32%via NVD
CVE-2026-1696Medium· 6.1
7mo ago

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

▾ Sunlitarcinfo · pcvueEPSS 0.15%via NVD
CVE-2026-1695Medium· 6.1
7mo ago

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into load…

▾ Sunlitarcinfo · pcvueEPSS 0.21%via NVD
CVE-2026-25896Critical· 9.3PoC⚖ disputed
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…

▾ Abyssalnaturalintelligence · fast-xml-parserEPSS 0.50%via NVD
CVE-2025-15267Medium· 6.4
7mo ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…

▾ Sunlitboldthemes · Bold Page BuilderEPSS 0.26%via NVD
CVE-2026-25640High· 7.1
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript …

▾ Twilightpydantic · pydantic_aiEPSS 0.41%via NVD
CVE-2026-20111Medium· 4.8
7mo ago

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

▾ Sunlitcisco · prime_infrastructureEPSS 0.19%via NVD
CVE-2025-69848Medium· 5.4PoC
7mo ago

NetBox is an open-source infrastructure resource modeling and IP address management platform

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object…

▾ Twilightnetbox · netboxEPSS 0.31%via NVD
CVE-2026-23960Medium· 5.4
8mo ago

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbit…

▾ Sunlitargoproj · argo_workflowsEPSS 0.40%via NVD
CVE-2026-21618Medium· 6.1
8mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is a…

▾ Sunlithex · hexpmEPSS 0.26%via NVD
CVE-2021-47839High· 7.2
8mo ago

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when t…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-22029High· 8.0
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, D…

▾ Twilightshopify · remix-run/reactEPSS 0.88%via NVD
CVE-2026-21884High· 8.2
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…

▾ Twilightshopify · react-routerEPSS 0.54%via NVD
CVE-2025-59057High· 7.6PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…

▾ Midnightshopify · react-routerEPSS 0.51%via NVD
CVE-2025-9222High· 8.7
8mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

▾ Twilightgitlab · gitlabEPSS 0.43%via NVD
CVE-2025-13761High· 8.0
8mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…

▾ Twilightgitlab · gitlabEPSS 0.71%via NVD
CVE-2025-15437Low· 3.5
8mo ago

A vulnerability was found in LigeroSmart up to 6.1.24

A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be i…

▾ Sunlitligerosmart · ligerosmartEPSS 0.28%via NVD
CVE-2025-67711Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-67710Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-67709Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-67708Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-67705Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-67704Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.25%via NVD
CVE-2025-67703Medium· 6.1
9mo ago

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in …

▾ Sunlitesri · arcgis_serverEPSS 0.24%via NVD
CVE-2025-53235High· 7.1
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3.

▾ TwilightEPSS 0.22%via NVD
CVE-2025-52739High· 7.1
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.

▾ TwilightEPSS 0.18%via NVD
CWE-79 vulnerabilities (CVEs) — page 56 · VulnSea