Export limit exceeded: 50015 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50015 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-95817 | 2026-10-02 | 7.2 High | ||
| The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post. | ||||
| CVE-2026-97663 | 2026-10-02 | 7.2 High | ||
| The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. | ||||
| CVE-2026-56005 | 2 Melapress, Wordpress | 2 Wp Activity Log, Wordpress | 2026-10-02 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows Stored XSS.This issue affects WP Activity Log: from n/a through 5.6.3.1. | ||||
| CVE-2026-73382 | 2 Geminilabs, Wordpress | 2 Site Reviews, Wordpress | 2026-10-02 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0. | ||||
| CVE-2026-93463 | 1 Basercms Users Community | 1 Basercms | 2026-10-02 | N/A |
| A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | ||||
| CVE-2026-103923 | 1 Katex | 1 Katex | 2026-10-01 | 4.7 Medium |
| KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object's prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2. | ||||
| CVE-2026-54049 | 1 Sakaiproject | 1 Sakai | 2026-10-01 | 8.7 High |
| Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0. | ||||
| CVE-2026-70560 | 1 Ultimatefosters | 1 Ultimatepos | 2026-10-01 | 5.4 Medium |
| Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin. | ||||
| CVE-2023-53983 | 1 Ateme | 7 Flamingo, Flamingo Xl, Flamingo Xl Firmware and 4 more | 2026-10-01 | 9.8 Critical |
| Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | ||||
| CVE-2026-55230 | 1 Givanz | 1 Vvveb | 2026-10-01 | 8.7 High |
| Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6. | ||||
| CVE-2026-97260 | 2 Maxfoundry, Wordpress-extensions | 2 Maxgalleria, Maxgalleria | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||
| CVE-2026-7176 | 1 Crocantickets | 1 Entradium | 2026-10-01 | N/A |
| CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event. | ||||
| CVE-2026-7175 | 1 Crocantickets | 1 Entradium | 2026-10-01 | N/A |
| CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page; | ||||
| CVE-2026-7174 | 1 Crocantickets | 1 Entradium | 2026-10-01 | N/A |
| CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the affected parameters, which executes when an event’s discount list page is displayed. Successful exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. | ||||
| CVE-2026-7173 | 1 Crocantickets | 1 Entradium | 2026-10-01 | N/A |
| CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page. * (Reflected XSS) The Description parameter in the endpoint /events/<event_name>/edit-general when attempting to create or modify an event without filling in all required fields. | ||||
| CVE-2026-64950 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards. | ||||
| CVE-2026-103540 | 2 Form Tools, Formtools | 2 Form Tools, Form Tools | 2026-10-01 | 6.3 Medium |
| A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2018-6882 | 1 Synacor | 1 Zimbra Collaboration Suite | 2026-10-01 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment. | ||||
| CVE-2018-19953 | 1 Qnap | 1 Qts | 2026-10-01 | 6.1 Medium |
| If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109. | ||||
| CVE-2026-62084 | 1 Jeff Starr | 1 User Submitted Posts | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | ||||