Export limit exceeded: 50012 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50012 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104477 | 1 Showdownjs | 1 Showdown | 2026-10-02 | 6.1 Medium |
| Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML. | ||||
| CVE-2026-94592 | 2026-10-02 | 8.4 High | ||
| Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed. | ||||
| CVE-2026-90443 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 5.4 Medium |
| A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. | ||||
| CVE-2026-100263 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.7 Medium |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-93367 | 2026-10-02 | 7.2 High | ||
| The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session. | ||||
| CVE-2026-84925 | 2026-10-02 | 6.1 Medium | ||
| The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox. | ||||
| CVE-2026-71454 | 1 Cwe-79 - Cross-site Scripting | 1 Capec-63 | 2026-10-02 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63. | ||||
| CVE-2026-103097 | 2 Geovision, Geovision Inc. | 2 Gv-eye, Gv-eye | 2026-10-02 | 7.5 High |
| An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key. | ||||
| CVE-2026-103096 | 2 Geovision, Geovision Inc. | 2 Gv-eye, Gv-eye | 2026-10-02 | 7.5 High |
| API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key. | ||||
| CVE-2026-97286 | 2026-10-02 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11. | ||||
| CVE-2026-93697 | 1 Webpros | 2 Cpanel, Wp Squared | 2026-10-02 | N/A |
| There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | ||||
| CVE-2026-27874 | 1 Johnson Controls | 1 Easyio Fs32 | 2026-10-02 | N/A |
| : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63. | ||||
| CVE-2026-27873 | 1 Johnson Controls | 2 Easy Io Fg, Easyio Fg | 2026-10-02 | N/A |
| - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52. | ||||
| CVE-2026-102626 | 1 Limesurvey | 1 Limesurvey | 2026-10-02 | N/A |
| An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding. | ||||
| CVE-2026-104414 | 1 Ghost | 1 Ghost | 2026-10-02 | 8.1 High |
| Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions. | ||||
| CVE-2026-93029 | 1 Webpros | 2 Cpanel, Wp Squared | 2026-10-02 | N/A |
| There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | ||||
| CVE-2026-104847 | 2026-10-02 | N/A | ||
| ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3. | ||||
| CVE-2026-77912 | 1 Github | 1 Enterprise Server | 2026-10-02 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result. Crafted Markdown could abuse same-origin JavaScript gadgets to bypass Content Security Policy and gain control of the page DOM when viewed by another user. Successful exploitation could allow an attacker to read content visible to the victim, extract embedded CSRF tokens, perform state-changing actions as the victim, and exfiltrate data through same-origin writes. The payload could also propagate to repositories and organizations where the victim had write access. This vulnerability affected supported GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported via the GitHub Bug Bounty program. | ||||
| CVE-2026-5782 | 2026-10-02 | 5.2 Medium | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-97336 | 2026-10-02 | 7.2 High | ||
| The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default. | ||||