Export limit exceeded: 49715 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49715 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73254 | 1 Cesanta | 1 Mongoose | 2026-09-29 | 5.4 Medium |
| Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the href but inserts the raw filesystem filename into the HTML link text. The browser executes the injected markup in the Mongoose origin, which can expose session data or permit actions as the victim. This issue is fixed in version 7.22. | ||||
| CVE-2026-4034 | 1 Tibco | 1 Administrator | 2026-09-29 | N/A |
| Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | ||||
| CVE-2026-84739 | 1 Gitlab | 1 Gitlab | 2026-09-29 | 8.7 High |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer. | ||||
| CVE-2026-82387 | 1 Apache | 1 Roller | 2026-09-29 | 5.4 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download. | ||||
| CVE-2026-7193 | 1 Shenzhen Dbit Network Equipment | 1 T-cpe301k 4g Mini Wifi Router | 2026-09-29 | N/A |
| A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to gain full root access to the device via the Telnet service (port 23) using static credentials. | ||||
| CVE-2026-76718 | 2026-09-29 | 8.2 High | ||
| A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. | ||||
| CVE-2026-45381 | 1 Tautulli | 1 Tautulli | 2026-09-29 | N/A |
| Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping that handles quotes and slashes but not backslashes. A backslash-quote sequence can terminate the string, so an unauthenticated attacker can send a crafted link that executes script in the Tautulli web context when an authenticated user follows it. This issue is fixed in version 2.17.2. | ||||
| CVE-2026-101270 | 2026-09-29 | N/A | ||
| Malicious HTML content could be injected into the help texts of various fields with organizer permissions. | ||||
| CVE-2023-22491 | 1 Gatsbyjs | 1 Gatsby-transformer-remark | 2026-09-29 | 8.1 High |
| Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present in gatsby-transformer-remark when passing input in data mode (querying MarkdownRemark nodes via GraphQL). Injected JavaScript executes in the context of the build server. To exploit this vulnerability untrusted/unsanitized input would need to be sourced by or added into a file processed by gatsby-transformer-remark. A patch has been introduced in `gatsby-transformer-remark@5.25.1` and `gatsby-transformer-remark@6.3.2` which mitigates the issue by disabling the `gray-matter` JavaScript Frontmatter engine. As a workaround, if an older version of `gatsby-transformer-remark` must be used, input passed into the plugin should be sanitized ahead of processing. It is encouraged for projects to upgrade to the latest major release branch for all Gatsby plugins to ensure the latest security updates and bug fixes are received in a timely manner. | ||||
| CVE-2026-49243 | 2026-09-29 | N/A | ||
| Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650. | ||||
| CVE-2026-46650 | 1 Laurent 22 | 1 Joplin | 2026-09-29 | 4.4 Medium |
| Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2. | ||||
| CVE-2026-84902 | 2 Kingaddons, Wordpress-extensions | 2 King Addons For Elementor, King Addons For Elementor | 2026-09-29 | 6.8 Medium |
| The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page. | ||||
| CVE-2026-85122 | 1 Wordpress-extensions | 1 Easy Form Builder | 2026-09-29 | 8.8 High |
| The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS. | ||||
| CVE-2026-85127 | 2 Vikwp, Wordpress-extensions | 2 Vikbooking Hotel Booking Engine & Pms, Vikbooking | 2026-09-29 | 8.8 High |
| The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation. | ||||
| CVE-2026-88825 | 1 Wordpress-extensions | 1 Igms Direct Booking | 2026-09-29 | 8.8 High |
| The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget. | ||||
| CVE-2026-79320 | 1 Stenciljs | 1 Core | 2026-09-29 | 6.1 Medium |
| Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the textContent property of such a component's host element causes the value to be parsed as HTML instead of being inserted as text. If an application writes attacker-controlled data to these host elements, the data can be interpreted as markup and script can execute in the context of the application's origin. | ||||
| CVE-2026-100753 | 1 Ordasoft.com | 1 Real Estate Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link. | ||||
| CVE-2026-101109 | 1 Ordasoft.com | 1 Vehicle Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page. | ||||
| CVE-2026-101111 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow. | ||||
| CVE-2026-102333 | 1 Cle-b | 1 Httpdbg | 2026-09-29 | 6.1 Medium |
| httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens. | ||||