CWE-83
CVEs classified under CWE-83, newest first.
11 CVEsRSS
CVE-2026-91127High· 8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…
CVE-2026-45733High· 8.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute…
CVE-2026-45118Critical· 9.3MyBB is free and open source forum software
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redir…
CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-49276HighKirby: Self cross-site scripting (self-XSS) in the writer field
Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-48591Mediumearmark: Stored XSS via unescaped HTML attribute values
earmark: Stored XSS via unescaped HTML attribute values
CVE-2026-53722MediumNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
GHSA-6xcg-6q43-rj2vLow· 6.1Duplicate Advisory: Exported session HTML could keep unsafe markdown links
Duplicate Advisory: Exported session HTML could keep unsafe markdown links
CVE-2026-8245Medium· 5.4Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}"…
Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}"…