CWE-79
CVEs classified under CWE-79, newest first.
2121 CVEsRSS
CVE-2026-88746High· 7.1idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.
idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.
CVE-2026-88745Medium· 6.1EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
CVE-2026-73546High· 7.4PoCEnvoy is an open source edge and service proxy designed for cloud-native applications
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values …
CVE-2026-49995Medium· 4.8PoCTautulli is a Python based monitoring and tracking tool for Plex Media Server
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript str…
CVE-2026-45381Medium· 5.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual…
CVE-2026-79320Medium· 6.1Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime
Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the te…
CVE-2026-91165Low· 2.4Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPost…
CVE-2026-58491Critical· 9.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler i…
CVE-2026-94488High· 8.2PoCTelegram Desktop before 6.9.4 allows XSS in the HTML exporter
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. How…
CVE-2026-58504Medium· 6.1draw.io is a configurable diagramming and whiteboarding application
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed …
CVE-2026-36468Medium· 6.1Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…
Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…
CVE-2026-36470Medium· 5.8CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.
CVE-2026-36472Medium· 5.2CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascrip…
CVE-2026-93339Medium· 5.4Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…
Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…
CVE-2026-94387Medium· 5.4Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can i…
CVE-2025-71419Medium· 5.4UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script …
CVE-2026-94372Medium· 6.3MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page
MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an …
CVE-2026-94211Low· 2.4PoCA vulnerability has been found in Hyve5 Leantime up to 3.9.8
A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …
CVE-2026-94373Medium· 6.3MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component
MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Be…
CVE-2026-94210Low· 3.5PoCA flaw has been found in Hyve5 Leantime up to 3.9.8
A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…
CVE-2026-91921Medium· 5.1Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform
Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the w…
CVE-2026-94277Medium· 6.3MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding
MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission …
CVE-2026-94150Low· 2.4PoCA security flaw has been discovered in Omega Solution HRM OS up to 20260717
A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…
CVE-2026-94145Low· 3.5PoCA vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…
CVE-2026-94045Low· 3.5PoCA security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0
A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argumen…
CVE-2026-94035Medium· 4.3PoCA vulnerability was determined in SourceCodester Drug Recommendation System 1.0
A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting…
CVE-2026-94034Low· 3.5A vulnerability was found in SourceCodester Drug Recommendation System 1.0
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the…
CVE-2026-94033Low· 3.5PoCA vulnerability has been found in SourceCodester Drug Recommendation System 1.0
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txt…
CVE-2026-94016Low· 2.4PoCA security flaw has been discovered in SourceCodester Drug Recommendation System 1.0
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross si…
CVE-2026-93977Low· 3.5PoCA vulnerability was determined in code-projects Assessment Management 1.0
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scri…