VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2121 CVEsRSS

CVE-2026-95586Medium· 6.5
4d ago

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

▾ SunlitThemefic · ultimate-addons-for-contact-form-7EPSS 0.16%via NVD
CVE-2026-93618Medium· 6.5
4d ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTricksEPSS 0.16%via NVD
CVE-2026-91775High· 7.4PoC
4d ago

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

▾ MidnightLimeSurvey · LimeSurveyEPSS 0.38%via NVD
CVE-2026-93769High· 7.2
4d ago

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a …

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a …

▾ TwilightHumhub · HumhubEPSS 0.28%via NVD
CVE-2026-18872Critical· 9.3
4d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script …

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.19%via NVD
CVE-2026-63001Medium· 4.8
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it whe…

▾ Sunlitredaxo · coreEPSS 0.18%via NVD
CVE-2026-63002Medium· 4.8PoC
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker wh…

▾ Twilightredaxo · coreEPSS 0.18%via NVD
CVE-2026-59167Critical· 10.0PoC
4d ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler…

▾ Abyssalsuneditor · suneditorEPSS 0.39%via NVD
CVE-2026-5696Medium· 5.9
4d ago

Reflected Cross-Site Scripting (XSS) in Microweber

Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user int…

▾ SunlitMicroweber · Administration panelEPSS 0.31%via NVD
CVE-2026-95626High· 8.3
4d ago

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, th…

▾ TwilightTauri · tauriEPSS 0.28%via NVD
CVE-2026-91999Medium· 6.1
4d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-91928Medium· 6.1
4d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-91852Medium· 6.1
4d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which f…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.21%via NVD
CVE-2026-73192Medium· 6.1
4d ago

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected…

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected…

▾ SunlitApache Software Foundation · Apache Sling XSSEPSS 0.17%via NVD
CVE-2026-5924Medium· 6.4
4d ago

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-con…

▾ Sunlitjetmonsters · Getwid – Gutenberg BlocksEPSS 0.26%via NVD
CVE-2026-91073Medium· 6.8
4d ago

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting a…

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting a…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-88997Medium· 6.8PoC
4d ago

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and a…

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and a…

▾ TwilightEPSS 0.29%via NVD
CVE-2026-86842Medium· 6.8
4d ago

The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content an…

The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content an…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-85006Medium· 6.8
4d ago

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject even…

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject even…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-15696Medium· 6.8
4d ago

The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts tha…

The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts tha…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-96258Medium· 4.3PoC
4d ago

A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722

A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argum…

▾ TwilightonSite internet GmbH · Auktion NG AuktionssoftwareEPSS 0.26%via NVD
CVE-2026-95957Medium· 4.3PoC
4d ago

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the arg…

▾ TwilightSourceCodester · Smart Attendance System with QR Code ScannerEPSS 0.27%via NVD
CVE-2026-18131High· 8.2
5d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.25%via NVD
CVE-2026-95812Medium· 6.1PoC
5d ago

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected …

▾ TwilightMacWarrior · clipbucket-v5EPSS 0.35%via NVD
CVE-2026-88020Medium· 6.1
5d ago

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

▾ SunlitAutonomy Logic · OpenPLC RuntimeEPSS 0.27%via NVD
CVE-2026-77912High· 7.4
5d ago

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

▾ TwilightGitHub · Enterprise ServerEPSS 0.45%via NVD
CVE-2026-76909Low· 2.1
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…

▾ SunlitUnleash · unleashEPSS 0.27%via NVD
CVE-2026-83801Medium· 5.4
5d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, an…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-77272Medium· 5.4
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an …

▾ Sunlitsooperset · mcp-atlassianEPSS 0.24%via NVD
CVE-2026-48361Medium· 6.1
5d ago

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when t…

▾ Sunlitadobe · connectEPSS 0.18%via NVD
CWE-79 vulnerabilities (CVEs) — page 6 · VulnSea