Export limit exceeded: 50014 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50014 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97265 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jetengine, Jetengine | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||
| CVE-2026-97290 | 2 Sayontan Sinha, Wordpress-extensions | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | ||||
| CVE-2026-100510 | 2 Boldgrid, Wordpress-extensions | 2 Post And Page Builder, Post And Page Builder By Boldgrid | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | ||||
| CVE-2026-102376 | 2 Wordpress-extensions, Wpmudev | 2 Branda, Branda | 2026-10-01 | 7.1 High |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | ||||
| CVE-2026-102391 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder, Jetformbuilder | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | ||||
| CVE-2026-89424 | 2 Inisev, Wordpress-extensions | 2 Duplicate Post, Duplicate Post | 2026-10-01 | 6.4 Medium |
| The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload. | ||||
| CVE-2026-97661 | 2 Scottpaterson, Wordpress-extensions | 2 Business Essentials For Contact Form 7, Business Essentials For Contact Form 7 | 2026-10-01 | 7.2 High |
| The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways. | ||||
| CVE-2026-103063 | 2 Wordpress-extensions, Wpmet | 2 Elementskit Elementor Addons Lite, Elementskit Elementor Addons | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | ||||
| CVE-2026-57858 | 2 Cal, Cal.com | 2 Cal.com, Cal.com Self-hosted (cal.diy) | 2026-10-01 | 8.9 High |
| Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events. | ||||
| CVE-2026-56128 | 1 Netgate | 3 Pfsense, Pfsense Ce, Pfsense Plus | 2026-10-01 | 5.4 Medium |
| pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value in /firewall_rules.php with only single-quote escaping applied, permitting double-quote breakout. The payload executes in the browser of any user with the Firewall: Rules privilege who views the rules list with the affected schedule attached. | ||||
| CVE-2026-56127 | 1 Netgate | 3 Pfsense, Pfsense Ce, Pfsense Plus | 2026-10-01 | 5.4 Medium |
| pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML sanitization, then rendered without encoding in the firewall log table in /status_logs_filter.php. The payload executes in the browser of any user with the Status: Logs: Firewall privilege who views the affected log entries. | ||||
| CVE-2026-56126 | 1 Netgate | 3 Pfsense, Pfsense Ce, Pfsense Plus | 2026-10-01 | 5.4 Medium |
| pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resolution, start-date, end-date, start-time, end-time, graph-type, invert, and refresh-interval are concatenated and written to the global pfSense XML configuration without sanitization, then echoed unsanitized into a JavaScript string context on page render. Because the setting is stored in the global configuration, the payload executes in the browser of every user who visits the Status: Monitoring page. | ||||
| CVE-2022-50787 | 1 Sound4 | 21 Big Voice2, Big Voice2 Firmware, Big Voice4 and 18 more | 2026-10-01 | 7.2 High |
| SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions without authentication. | ||||
| CVE-2022-50696 | 3 Linux, Microsoft, Sound4 | 23 Linux, Windows, Big Voice2 and 20 more | 2026-10-01 | 9.8 Critical |
| SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction. | ||||
| CVE-2017-20234 | 2 Belden, Garrettcom | 2 Garrettcom Magnum 6k And 10k Managed Switches, Magnum Managed Networks Software-6k | 2026-10-01 | 9.8 Critical |
| GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and sensitive switch configuration without valid credentials. | ||||
| CVE-2026-96268 | 2 Getawesomesupport, Wordpress-extensions | 2 Awesome Support, Awesome Support | 2026-10-01 | 6.4 Medium |
| The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php. | ||||
| CVE-2026-90992 | 2 Davidanderson, Wordpress-extensions | 2 Redux Framework, Redux Framework | 2026-10-01 | 6.4 Medium |
| The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel. | ||||
| CVE-2026-85235 | 2 Wordpress-extensions, Wpmudev | 2 Forminator Forms, Forminator Forms | 2026-10-01 | 7.2 High |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session. | ||||
| CVE-2026-103589 | 1 Webkul | 1 Qloapps | 2026-10-01 | 5.4 Medium |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session. | ||||
| CVE-2026-101925 | 2 Robin-w, Wordpress-extensions | 2 Bbp Style Pack, Bbp Style Pack | 2026-10-01 | 6.4 Medium |
| The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a <pre> block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection. | ||||