VulnSea

CWE-87

CVEs classified under CWE-87, newest first.

6 CVEsRSS

CVE-2026-79946Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access coul…

Sunlitdell · secure_connect_gatewayEPSS 0.21%via NVD
CVE-2025-46571Medium
2mo ago

Open WebUI allows limited stored XSS vila uploaded html file

Open WebUI allows limited stored XSS vila uploaded html file

Sunlitopen-webui · open-webuiEPSS 0.35%via GHSA
CVE-2026-55661Medium
3mo ago

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Sunlittinacms · tinacmsEPSS 0.40%via GHSA
CVE-2026-54002High
3mo ago

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Twilightgetkirby · getkirby/cmsEPSS 0.55%via GHSA
CVE-2025-14732Medium· 6.4
5mo ago

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitiza…

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitiza…

SunlitEPSS 0.34%via NVD
CVE-2026-22711None
5mo ago

Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches …

Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches …

SunlitEPSS 0.29%via NVD
CWE-87 vulnerabilities (CVEs) · VulnSea