By weakness (CWE)

CWE-79: related vulnerabilities

CVEs classified under CWE-79. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

261 published vulnerabilities · page 2 of 3

  • CVE-2026-21825MEDIUM 6.1

    HCL Digital Experience and Digital Experience Compose contain a reflected cross-site scripting (XSS) vulnerability in their search center functionality. An attacker can craft a malicious link containing JavaScript code and trick a user into clicking it. When the victim visits the link, the attacker's script executes in their browser with their privileges, potentially stealing session cookies, credentials, or performing actions on their behalf. This vulnerability requires user interaction—the victim must click a malicious link—which somewhat limits its reach, but the ability to target any user makes it a meaningful risk for organizations relying on these platforms.

  • CVE-2026-2425MEDIUM 6.1

    The hiWeb Migration Simple WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in how it handles the 'new_domain' parameter. An attacker can craft a malicious link and trick a WordPress administrator into clicking it, causing arbitrary JavaScript to execute in the admin's browser session. This could allow the attacker to steal session tokens, modify site content, or perform administrative actions on behalf of the compromised admin. The vulnerability affects all versions through 2.0.0.1.

  • CVE-2026-29170MEDIUM 6.1

    Apache HTTP Server versions 2.4.67 and earlier contain a cross-site scripting (XSS) vulnerability in the mod_proxy_ftp module. When the server is configured to proxy FTP directory listings—whether forwarding traffic to an upstream FTP server or presenting one via reverse proxy—it fails to properly sanitize HTML generated for directory contents. An attacker can craft malicious FTP directory entries or filenames containing JavaScript code. When an administrator or user views the directory listing in a browser, the malicious script executes in their session, potentially allowing session hijacking, credential theft, or administrative actions.

  • CVE-2026-30586MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in usememos Memos version 0.26.0 that allows an attacker to inject malicious code into memo pages. When a user views a compromised memo—whether public or private—the attacker's script executes in the user's browser, potentially exposing sensitive information. The vulnerability stems from improper sanitization of user input in the memo rendering component, meaning the application fails to adequately strip or encode dangerous HTML and JavaScript before displaying memo content.

  • CVE-2026-33553MEDIUM 6.1

    Northern.tech CFEngine Enterprise contains a cross-site scripting (XSS) vulnerability in versions 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1. An attacker can inject malicious scripts that execute in the browser context of users interacting with the CFEngine Enterprise interface, potentially compromising user sessions or stealing sensitive information without requiring authentication.

  • CVE-2026-35212MEDIUM 6.1

    OpenCTI, an open-source threat intelligence platform, contains a cross-site scripting (XSS) vulnerability in how it renders email message data. An attacker can craft a malicious email observable with unsanitized content in the message body, which executes JavaScript in a victim's browser when they view it. Because threat intelligence is often shared across teams via STIX files or automated ingesters, this could be weaponized to steal session cookies at scale, potentially compromising multiple analysts' accounts. The vulnerability requires user interaction—someone must view the crafted email observable—but the attack surface is broad given how threat intelligence is typically distributed.

  • CVE-2026-36324MEDIUM 6.1

    SourceCodester Doctor Appointment System version 1.0 contains a Cross-Site Scripting (XSS) vulnerability in its user registration form. An attacker can inject malicious scripts into the registration page, which are then executed in the browsers of other users who view that registration data. This allows the attacker to steal session cookies, redirect users to phishing sites, or perform actions on behalf of legitimate users without their knowledge.

  • CVE-2026-38579MEDIUM 6.1

    Damasac Thaipalliative LTE through version 3.0 contains multiple reflected cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts into web pages viewed by users. The flaws exist in the /substudy/ezform.php file where user-supplied values are directly inserted into HTML without proper sanitization. An attacker can craft a malicious URL and trick a user into clicking it, causing arbitrary JavaScript to execute in that user's browser within the context of the vulnerable application.

  • CVE-2026-41539MEDIUM 6.1

    QNAP has patched a cross-site scripting (XSS) vulnerability affecting multiple versions of QTS and QuTS hero operating systems. The flaw allows remote attackers to inject malicious scripts that execute in users' browsers, potentially bypassing security controls or stealing sensitive application data. No authentication is required to attempt exploitation, but a user must be tricked into clicking a malicious link or visiting a compromised page. QNAP has released security updates addressing the issue across affected product lines.

  • CVE-2026-42253MEDIUM 6.1

    Apache ActiveMQ's web console contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious content into HTTP response headers. The flaw exists in how the MessageServlet handles JMS message properties—it copies them directly into HTTP headers without filtering or validation. An attacker who can craft a JMS message with specially crafted properties could inject security headers, potentially leading to session hijacking, credential theft, or malware delivery when a user views the affected web console. The vulnerability requires user interaction (a victim must view the injected content) and affects versions of ActiveMQ and ActiveMQ Web released before 5.19.7 and 6.2.6.

  • CVE-2026-42573MEDIUM 6.1

    Svelte, a lightweight and performance-focused web framework, contained a vulnerability in versions before 5.55.7 that allowed attackers to manipulate the browser's DOM in a way that corrupted Svelte's internal state. By exploiting DOM clobbering—a technique where attackers inject HTML elements that shadow legitimate JavaScript objects—an attacker could potentially inject malicious scripts that execute in a user's browser, leading to cross-site scripting (XSS) attacks. The vulnerability requires user interaction, such as clicking a link or visiting a malicious page, to be triggered.

  • CVE-2026-42599MEDIUM 6.1

    Svelte, a popular web framework, contains a vulnerability where untrusted data rendered as HTML attributes can include malicious event handlers. If your application uses Svelte's spread syntax to render attributes from user input or external sources, attackers could inject code that runs when users interact with those elements. The risk is reduced if Svelte's hydration process completes before the injected event fires, but this shouldn't be relied upon as a defense. Version 5.55.7 and later address this issue.

  • CVE-2026-44746MEDIUM 6.1

    SAP NetWeaver JAVA contains a reflected cross-site scripting (XSS) vulnerability in its JDBC Test Servlet component. An attacker can craft a malicious URL containing embedded script code. When an unsuspecting user clicks this link, the script executes in their browser within the context of the affected application. This allows the attacker to steal session data, modify information displayed to the user, or perform unauthorized actions on behalf of the victim—all without requiring the attacker to authenticate or exploit a server-side flaw. The vulnerability requires user interaction (clicking a link) to be triggered.

  • CVE-2026-45500MEDIUM 6.1

    Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages served by the application. An attacker can exploit this by crafting a malicious link or embedding code in a page that, when visited by a user, executes arbitrary actions in that user's browser session—such as stealing credentials, impersonating the user, or modifying email content. The vulnerability requires user interaction (clicking a link or visiting a page) but can affect any Exchange Server deployment exposed to the internet or accessible via webmail interfaces.

  • CVE-2026-49375MEDIUM 6.1

    JetBrains TeamCity versions before 2026.1 and 2025.11.5 contain a reflected cross-site scripting (XSS) vulnerability on the repository download page. An attacker can craft a malicious URL and trick a user into clicking it, allowing the attacker to steal session cookies, perform actions on behalf of the user, or redirect them to phishing sites. The vulnerability requires user interaction and does not directly compromise the server itself.

  • CVE-2026-49384MEDIUM 6.1

    JetBrains PyCharm versions prior to 2025.3.4 contain a stored cross-site scripting (XSS) vulnerability in Jupyter notebook Markdown cells. An attacker can inject malicious scripts into Markdown content within a notebook, which are then executed in the browser context of users who view the notebook. This allows for session hijacking, credential theft, or malware distribution without requiring the victim to take any action beyond opening an affected notebook.

  • CVE-2026-50230MEDIUM 6.1

    Lyrion Music Server version 9.2.0 has a cross-site scripting (XSS) vulnerability in its server logging endpoint. An attacker can craft a malicious URL containing JavaScript code and trick a user into clicking it. When the user visits the link, the JavaScript runs in their browser with the same permissions as the Lyrion application, potentially allowing the attacker to steal session cookies, redirect the user, or perform actions on their behalf. No authentication is required to exploit this vulnerability, making it accessible to anyone who can send a link to a target user.

  • CVE-2026-50235MEDIUM 6.1

    Lyrion Music Server 9.2.0 has a reflected cross-site scripting (XSS) vulnerability in its advanced search feature. An attacker can craft a malicious link containing JavaScript code in the search parameters. When a user clicks the link or is tricked into visiting it, the malicious script executes in their browser, potentially allowing the attacker to steal session cookies, hijack accounts, or perform actions on behalf of the user. The vulnerability requires user interaction—the victim must click a malicious link—but no special privileges or complex setup are needed to exploit it.

  • CVE-2026-7660MEDIUM 6.1

    The Easy Updates Manager WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in its pagination feature. Attackers can craft malicious links that inject JavaScript code into pages. When a WordPress administrator clicks such a link, the injected script executes in their browser with their privileges, potentially allowing attackers to steal credentials, modify site content, or perform unauthorized actions. The vulnerability affects versions 9.0.20 and earlier.

  • CVE-2026-9280MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability exists in the Ad Inserter – Ad Manager & AdSense Ads WordPress plugin affecting all versions up to 2.8.15. The flaw allows attackers to inject malicious scripts into web pages by crafting a deceptive link. If a user clicks the link while viewing a page with the plugin's iframe mode enabled, the attacker's script executes in their browser. This attack requires no special permissions and relies on social engineering to succeed.

  • CVE-2026-28116MEDIUM 5.9

    Emilia Projects Progress Planner versions 1.9.0 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts into the application. When other users view affected pages, the injected code executes in their browsers, potentially enabling session hijacking, credential theft, or further lateral movement within the application environment.

  • CVE-2026-41846MEDIUM 5.9

    Spring Framework contains a reflected cross-site scripting (XSS) vulnerability in its JSP form tag library. When developers use Spring MVC form tags and bind user-supplied input to the cssClass, cssErrorClass, or cssStyle attributes without proper sanitization, an attacker can inject malicious HTML and JavaScript code. This code executes in the victim's browser when they view the affected page, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (such as clicking a malicious link) to trigger.

  • CVE-2026-25624MEDIUM 5.7

    A cross-site scripting (XSS) vulnerability exists in Arista Next Generation Firewall's administrative dashboard. An attacker with administrative credentials can inject malicious code into web form fields that are then reflected back to other administrators viewing the dashboard, potentially allowing them to steal session tokens, modify firewall rules, or perform other administrative actions on behalf of legitimate users. This is a stored or reflected XSS issue that requires an attacker to have already compromised an admin account or trick an admin into clicking a malicious link.

  • CVE-2025-5085MEDIUM 5.5

    The WP Nano AD plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability affecting versions 1.31 and earlier. An authenticated administrator can inject malicious scripts through the 'blogrole_link' parameter that persist in the database and execute in the browsers of users who view affected pages. The vulnerability is limited to WordPress multisite installations or those with the 'unfiltered_html' capability disabled, which narrows its real-world scope but makes it critical for affected deployments.

  • CVE-2018-25384MEDIUM 5.4

    Wikidforum 2.20 has a stored cross-site scripting (XSS) flaw that lets authenticated users inject malicious JavaScript into forum replies. When other users view those compromised posts through the rpc.php endpoint, the injected code executes in their browsers, potentially stealing session cookies, redirecting to phishing pages, or performing unauthorized actions on their behalf.

  • CVE-2019-25739MEDIUM 5.4

    GigToDo version 1.3 is vulnerable to a stored cross-site scripting (XSS) attack. An authenticated user can inject malicious JavaScript or HTML code into a proposal description field. When other users—particularly administrators—view that proposal, the attacker's code executes in their browser, potentially stealing session cookies or redirecting them to malicious sites. The vulnerability requires an attacker to already have valid login credentials, but the impact affects anyone who later views the compromised proposal.

  • CVE-2019-25742MEDIUM 5.4

    The Zoner Real Estate WordPress theme version 4.1.1 has a stored cross-site scripting (XSS) flaw in its property creation form. Authenticated real estate agents can inject malicious JavaScript into the property's address field, and that script will execute when site administrators review the property for approval. This could allow attackers to steal admin session cookies or hijack their accounts.

  • CVE-2019-25743MEDIUM 5.4

    WordPress Soliloquy Lite version 2.5.6 contains a stored cross-site scripting (XSS) vulnerability in its post editing functionality. An authenticated attacker can inject malicious JavaScript code into a post's title field, which persists in the WordPress database. When other users—particularly administrators or editors—preview that post, the injected script executes in their browser, potentially compromising their session or enabling further attacks. The vulnerability requires an attacker to have valid WordPress credentials but does not require tricking users into clicking malicious links, making it a genuine persistence risk in multi-user WordPress environments.

  • CVE-2019-25744MEDIUM 5.4

    WordPress Popup Builder version 3.49 contains a stored cross-site scripting (XSS) flaw that allows authenticated users to inject malicious JavaScript into posts or pages. An attacker with WordPress login credentials can craft a specially formatted post title containing script code that breaks out of HTML option tags, causing the malicious script to execute in the browsers of site visitors viewing popup selections. This is a persistence vulnerability—the injected code remains in the database and executes repeatedly.

  • CVE-2026-11569MEDIUM 5.4

    Quay, a container image registry platform, contains a vulnerability in its file upload endpoint that fails to properly validate file types. An authenticated user with write access to a repository can exploit this to upload a malicious SVG file containing embedded JavaScript code. Because the file is stored and then served inline by the CDN without proper content-type restrictions, any user visiting the archive URL will have that JavaScript execute in their browser—a stored cross-site scripting attack. The vulnerability requires an attacker to already have repository write permissions and the victim to click a link, which limits but does not eliminate risk in collaborative development environments.

  • CVE-2026-24754MEDIUM 5.4

    Kiteworks, a private data network platform used for secure file sharing and collaboration, contains a stored cross-site scripting (XSS) vulnerability in its Secure Data Forms feature. An authenticated user with legitimate access could craft malicious input that persists in the application and executes in other users' browsers when they view the affected form. This allows the attacker to steal session tokens, perform actions on behalf of victims, or harvest sensitive data passing through their sessions. The vulnerability requires prior authentication and user interaction (clicking a link or viewing a page), limiting but not eliminating its risk. Kiteworks versions before 9.3.0 are affected; upgrading resolves the issue.

  • CVE-2026-26378MEDIUM 5.4

    Koha, an open-source library management system, contains a cross-site scripting (XSS) vulnerability in its Invoice feature file upload functionality. An authenticated attacker can craft a malicious file upload that executes arbitrary code in the browsers of users who interact with the uploaded invoice. The vulnerability affects Koha version 25.11 and earlier. Exploitation requires an attacker to have valid library system credentials and user interaction—typically a staff member viewing or processing the invoice.

  • CVE-2026-33113MEDIUM 5.4

    Microsoft Office SharePoint contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When a user visits a compromised SharePoint page, the injected code executes in their browser, potentially allowing the attacker to steal session tokens, redirect users to phishing sites, or perform actions on behalf of the victim. This is a reflected or stored XSS flaw—the vulnerability itself requires user interaction to trigger, but the impact can be significant for organizations relying on SharePoint for document collaboration and intranet services.

  • CVE-2026-33244MEDIUM 5.4

    React Router versions 7.5.1 through 7.13.1 contain a cross-site scripting (XSS) vulnerability when used in Framework Mode with pre-rendering. If your application redirects users to untrusted URLs and generates static HTML files during build time, attackers can inject malicious scripts into those pre-rendered pages. This vulnerability does not affect applications using the more common Declarative Mode or Data Mode routing approaches. The issue has been fixed in version 7.13.2.

  • CVE-2026-34033MEDIUM 5.4

    Apache Answer contains a cross-site scripting (XSS) vulnerability in its notification email system. When authenticated users include content in certain fields, that content reaches other users' inboxes without proper HTML escaping, potentially allowing injection of malicious scripts. An attacker with valid credentials could craft messages designed to execute code when recipients open their emails or click embedded links. This affects Apache Answer versions through 2.0.0.

  • CVE-2026-34692MEDIUM 5.4

    Adobe Experience Manager contains a cross-site scripting (XSS) flaw that allows attackers to inject and execute malicious JavaScript in a user's browser. The attack requires tricking a victim into visiting a specially crafted webpage while authenticated to AEM. Once executed, the attacker can steal session data, modify page content, or perform actions on behalf of the victim within the AEM interface.

  • CVE-2026-45453MEDIUM 5.4

    CVE-2026-45453 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. When a user visits a compromised page, the attacker's script executes in their browser, enabling spoofing attacks—such as stealing credentials, impersonating legitimate content, or redirecting users to phishing sites. The vulnerability requires user interaction (clicking a malicious link or visiting a crafted URL) but does not require authentication to exploit.

  • CVE-2026-45464MEDIUM 5.4

    CVE-2026-45464 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. An attacker can trick users into visiting a crafted SharePoint page, causing their browser to execute the injected code. This enables spoofing attacks where legitimate content or UI elements can be forged to deceive users into divulging credentials, transferring funds, or trusting false information. The vulnerability requires user interaction—a person must click a malicious link or visit a compromised page—but the attacker does not need authentication to craft the attack.

  • CVE-2026-45465MEDIUM 5.4

    CVE-2026-45465 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an attacker to inject malicious code into web pages generated by the application. When a user visits a compromised page, the injected script executes in their browser, potentially stealing session tokens, credentials, or performing actions on behalf of the victim. The vulnerability requires user interaction—someone must click a malicious link or visit a booby-trapped SharePoint page—but no special privileges are needed to launch the attack. This is a spoofing risk, meaning attackers could impersonate legitimate SharePoint content or trusted users.

  • CVE-2026-45580MEDIUM 5.4

    WWBN AVideo, an open-source video streaming platform, contains a stored cross-site scripting (XSS) vulnerability in its Live plugin. A user with streaming permissions can inject malicious JavaScript into the stream configuration, which then executes in the browsers of anyone—logged-in or anonymous—who views that live stream. The vulnerability persists because user-controlled input (the stream key) is inserted directly into an HTML class attribute without proper sanitization.

  • CVE-2026-45778MEDIUM 5.4

    OpenXDMoD, an open-source HPC (High Performance Computing) metrics collection and analysis framework, contains a stored cross-site scripting (XSS) vulnerability in user profiles combined with a password reset abuse vector. An authenticated attacker can inject malicious JavaScript into their profile, then weaponize the password reset feature to send victims a crafted link. When a victim clicks the link, the attacker's payload executes in their browser, enabling credential theft and account hijacking. All versions prior to 11.0.3 are affected.

  • CVE-2026-47636MEDIUM 5.4

    CVE-2026-47636 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. When a user visits a specially crafted SharePoint page, the injected code executes in their browser with their privileges, enabling attackers to impersonate users, steal session data, or perform actions on their behalf. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require authentication to exploit.

  • CVE-2026-47639MEDIUM 5.4

    CVE-2026-47639 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an attacker to inject malicious scripts into web pages. When a user visits a compromised page, the attacker's script executes in their browser, potentially stealing credentials, session tokens, or sensitive data, or redirecting users to fraudulent sites. Exploitation requires user interaction—the victim must click a link or visit a crafted page—but no authentication is needed from the attacker's side.

  • CVE-2026-47694MEDIUM 5.4

    WWBN AVideo, an open-source video platform, contains a stored cross-site scripting (XSS) vulnerability in how it handles category descriptions. Any user with permission to create or modify video categories can inject malicious JavaScript code into the description field. This code then executes in the browsers of other users who view that category's gallery page. Unlike previously patched XSS issues affecting video titles or comments, this flaw specifically targets the category description rendering pipeline.

  • CVE-2026-47935MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows an attacker to inject malicious JavaScript code into a victim's browser session. The vulnerability affects multiple versions up to 6.5.24, LTS SP1, and 2026.04. An attacker must trick a user into visiting a specially crafted webpage to trigger the exploit, but once executed, the malicious script runs with the victim's privileges and can access or modify sensitive data within the AEM application context across different origin boundaries.

  • CVE-2026-47936MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user permissions to embed malicious code into form fields. When other users view those pages, the attacker's JavaScript runs in their browsers. This is particularly concerning because the injected script can affect other domains or applications (indicated by the changed scope), potentially compromising session tokens or sensitive data from multiple contexts.

  • CVE-2026-47939MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers. This is a persistence threat—the malicious payload remains in the system until remediated, affecting anyone who accesses the affected content.

  • CVE-2026-47941MEDIUM 5.4

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged user can inject malicious JavaScript that persists in the application and executes in other users' browsers when they view the affected page. This is a persistence problem: the attack code lives in the application, not just in a URL or temporary input. The scope change means the XSS can affect resources beyond the vulnerable component itself.

  • CVE-2026-47942MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level user access to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers. This represents a medium-severity risk because it requires both initial low-privileged access and user interaction, but affects multiple versions of a widely-deployed content management platform.

  • CVE-2026-47943MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting vulnerability affecting versions 6.5.24, LTS SP1, 2026.04 and earlier. A user with low-level permissions can inject malicious JavaScript code into form fields, which then executes when other users view the affected page. This is particularly risky because the malicious payload persists in the system rather than being temporary, and it affects the security boundary between different parts of the application (indicated by the scope change in the CVSS vector). The attack requires user interaction—victims must browse to the page containing the injected field—but the damage is real: attackers can steal session tokens, capture credentials, or perform unauthorized actions on behalf of victims.

  • CVE-2026-47944MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript code into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers. This is a persistence issue—the malicious payload remains in the system until removed, affecting anyone who accesses the affected content.

  • CVE-2026-47945MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When legitimate users view pages containing these compromised fields, the malicious script executes in their browsers, potentially compromising their sessions, stealing credentials, or performing unauthorized actions on their behalf. The vulnerability affects multiple versions of AEM through version 2026.04 and earlier LTS releases.

  • CVE-2026-47946MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based Cross-Site Scripting vulnerability that allows an attacker to inject malicious JavaScript code into a victim's browser session. The attack requires a logged-in user to visit a specially crafted webpage, at which point the attacker's script executes with the victim's privileges within the AEM application context. This can lead to unauthorized actions, data theft, or session hijacking depending on the victim's role and permissions.

  • CVE-2026-47947MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows attackers to inject malicious JavaScript into web pages viewed by authenticated users. The vulnerability affects multiple AEM versions through 6.5.24, LTS SP1, and 2026.04. Successful exploitation requires convincing a user to visit an attacker-controlled or compromised webpage while logged into an affected AEM instance. The attacker's code would then execute with the victim's privileges, potentially stealing session data, modifying content, or performing actions on their behalf.

  • CVE-2026-47948MEDIUM 5.4

    Adobe Experience Manager versions up to 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (viewing the affected page) and a valid login, but can impact users across different security contexts.

  • CVE-2026-47949MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with basic user privileges to inject malicious JavaScript. When legitimate users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially enabling session hijacking, credential theft, or further compromise. The vulnerability affects AEM 6.5.24, LTS SP1, 2026.04, and earlier versions.

  • CVE-2026-47950MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) flaw that allows low-privileged users to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript runs in their browsers with the victim's permissions. The vulnerability affects multiple AEM versions including 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-47951MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows attackers with low-level account privileges to embed malicious code into form fields. When other users visit pages containing these compromised fields, the injected scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information. The vulnerability affects multiple AEM versions up to and including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47953MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows low-privileged users to inject malicious scripts. When a victim visits a page containing an affected form field, the injected script executes in their browser with the victim's privileges, potentially compromising their session or stealing sensitive data. The vulnerability affects multiple versions of AEM through 2026.04 and requires authenticated access to exploit, limiting but not eliminating the attack surface.

  • CVE-2026-47954MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user privileges to embed malicious code into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially allowing the attacker to steal credentials, session tokens, or perform actions on behalf of the victim. The vulnerability affects multiple versions of AEM up to and including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47956MEDIUM 5.4

    Adobe Experience Manager versions through 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw in form field handling. An attacker with basic user privileges can inject malicious JavaScript into vulnerable fields. When legitimate users view pages containing these fields, the injected scripts execute in their browsers. This is particularly concerning because the vulnerability changes scope—meaning an attacker could potentially affect other users or system functionality beyond the immediate form context.

  • CVE-2026-47957MEDIUM 5.4

    Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. An attacker with low-level system access can inject malicious JavaScript that persists in the application and executes whenever a user views the affected page, potentially allowing credential theft, session hijacking, or malware distribution. The vulnerability requires user interaction—a victim must navigate to the compromised form—but the attacker does not need elevated privileges to introduce the payload.

  • CVE-2026-47958MEDIUM 5.4

    Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged user can inject malicious JavaScript that persists in the application and executes when other users view the affected page. Because the vulnerability has a changed scope—meaning the impact crosses trust boundaries—it affects not just the immediate application but potentially other parts of the system or connected domains.

  • CVE-2026-47962MEDIUM 5.4

    Adobe Experience Manager is vulnerable to a stored cross-site scripting (XSS) attack where a low-privileged user can inject malicious JavaScript code into form fields. When other users—including administrators or content editors—view the page containing the compromised field, the malicious script executes in their browser. This can lead to credential theft, session hijacking, or unauthorized actions performed on behalf of the victim.

  • CVE-2026-47966MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw in form field handling. An attacker with low-level access can inject malicious JavaScript that persists in the application. When other users view the compromised form, the injected script executes in their browsers, potentially allowing credential theft, session hijacking, or further compromise. The vulnerability affects multiple versions through 2026.04 and earlier.

  • CVE-2026-47970MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with basic user privileges to inject malicious scripts. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers, potentially stealing data or performing unauthorized actions. The vulnerability affects multiple AEM versions through 2026.04.

  • CVE-2026-47972MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored Cross-Site Scripting flaw that allows low-privileged users to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's script executes in their browsers, potentially compromising sessions, stealing credentials, or performing actions on their behalf. The vulnerability affects multiple AEM versions through 2026.04.

  • CVE-2026-47973MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers, potentially stealing credentials, session tokens, or sensitive data. The vulnerability affects multiple versions of AEM, including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47974MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability that allows attackers with low-level user access to inject malicious JavaScript into form fields. When other users view those compromised pages, the malicious code runs in their browsers. This is a scope-change vulnerability, meaning an attacker can potentially affect users beyond their normal permission level. The vulnerability affects multiple recent versions of AEM.

  • CVE-2026-47975MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows attackers with basic user privileges to inject malicious scripts into form fields. When legitimate users visit pages containing these compromised fields, the attacker's JavaScript executes in their browsers. This is distinct from reflected XSS because the malicious payload persists in the application's database, affecting all subsequent visitors. The vulnerability requires user interaction—a victim must view the poisoned page—but the attacker needs only low-level access to inject the payload initially.

  • CVE-2026-47977MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw in certain form fields. An attacker with low-level system access can embed malicious JavaScript into these fields, and that script executes automatically when other users view the affected page. The vulnerability requires user interaction (victims must visit the page), but the stored nature means the attack persists and affects anyone who accesses the compromised content.

  • CVE-2026-47978MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level account privileges to embed malicious scripts into form fields. When legitimate users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers, potentially compromising their sessions or stealing sensitive data. This is a *stored* vulnerability, meaning the malicious payload persists in the application until remediated—unlike reflected XSS that requires a crafted link. The vulnerability affects AEM versions 6.5.24, LTS SP1, 2026.04, and earlier.

  • CVE-2026-47980MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows low-privileged users to inject malicious scripts. When a victim visits a page containing an affected form field, the injected JavaScript executes in their browser, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on behalf of the victim. The vulnerability affects versions 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-47981MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows attackers with basic user privileges to embed malicious code into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information. The vulnerability affects AEM versions 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-47982MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a cross-site scripting (XSS) flaw in versions 6.5.24, LTS SP1, 2026.04 and earlier. An attacker can craft a malicious webpage that, when visited by an authenticated AEM user, executes arbitrary JavaScript in the user's browser session. The attack manipulates the page's DOM to inject and run hostile code, potentially allowing the attacker to steal session tokens, modify content, or perform actions on behalf of the victim. Because exploitation requires the victim to actively visit a malicious page, this is a lower-risk variant of XSS, but it can still escalate to account compromise or unauthorized modifications within AEM.

  • CVE-2026-47983MEDIUM 5.4

    Adobe Experience Manager contains a vulnerability that allows attackers to inject and execute malicious JavaScript code in a victim's browser through specially crafted webpages. The attack requires a user to be logged in (or have an authenticated session) and to visit a malicious link or page, but once that happens, the attacker can steal session data, modify page content, or perform actions on behalf of the victim within the AEM environment. This is a DOM-based XSS vulnerability, meaning the malicious code manipulates how the browser's Document Object Model is rendered rather than relying on unsanitized server-side output.

  • CVE-2026-47985MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a vulnerability where attackers can inject malicious JavaScript that runs in a user's browser when they visit a specially crafted webpage. The attack exploits how the application handles dynamic content in the browser's DOM (Document Object Model), allowing an attacker to steal session data, redirect users, or perform actions on their behalf within AEM. This requires the victim to click a link or visit a page—the attacker cannot force exploitation remotely. The vulnerability affects multiple versions of AEM up to and including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47986MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious JavaScript code into web pages viewed by authenticated users. The vulnerability affects versions 6.5.24, LTS SP1, 2026.04 and earlier. An attacker must trick a user into visiting a specially crafted webpage while that user is logged into AEM; the malicious script then executes in the user's browser with their privileges. This can lead to unauthorized actions, data theft, or further compromise depending on the victim's role and permissions.

  • CVE-2026-47987MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into web pages. The flaw affects versions 6.5.24, LTS SP1, 2026.04 and earlier. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the vulnerability. Once executed, the attacker's code runs in the victim's browser with the same privileges as the logged-in user, potentially allowing unauthorized actions or data theft.

  • CVE-2026-47989MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw in versions 6.5.24, LTS SP1, 2026.04 and earlier. An attacker can craft a malicious webpage that, when visited by an authenticated user, executes arbitrary JavaScript in the victim's browser. This runs within an elevated scope—meaning the attacker gains access to resources and data the victim can access, potentially beyond what a typical reflected XSS would permit. The flaw requires user interaction but poses meaningful risk in multi-tenant or content-collaboration environments where AEM is deployed.

  • CVE-2026-47990MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability that allows attackers with basic system access to plant malicious code in form fields. When legitimate users view affected pages, the injected scripts execute in their browsers, potentially compromising sessions, stealing data, or triggering unwanted actions. The vulnerability affects AEM versions 6.5.24, LTS SP1, and 2026.04 and earlier.

  • CVE-2026-47993MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) vulnerability that allows an attacker to inject and execute malicious JavaScript in a victim's browser. The attack requires the victim to visit a crafted webpage while authenticated to AEM. Because the vulnerability changes the scope of impact, an attacker could potentially affect resources beyond the vulnerable application itself. This is not currently being exploited in the wild according to public threat databases.

  • CVE-2026-48250MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based Cross-Site Scripting (XSS) vulnerability that allows attackers to inject and execute malicious JavaScript in a victim's browser. The vulnerability affects multiple AEM versions (6.5.24, LTS SP1, 2026.04 and earlier) and requires an authenticated user to visit a specially crafted webpage. While the attack requires user interaction and authentication, the scope change means the attacker's privileges can impact resources beyond the vulnerable application itself.

  • CVE-2026-48251MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a vulnerability that allows attackers to inject malicious scripts into the DOM, which execute in users' browsers. This DOM-based cross-site scripting (XSS) flaw affects multiple versions of AEM up to and including 6.5.24, LTS SP1, and 2026.04. Exploitation requires an attacker to trick a user into visiting a specially crafted webpage, making it dependent on user interaction. Once the malicious page loads, the attacker's JavaScript runs within the victim's browser session, potentially allowing theft of session tokens, credential capture, or unauthorized actions on behalf of the user.

  • CVE-2026-48256MEDIUM 5.4

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a DOM-based cross-site scripting (XSS) flaw. An attacker can craft a malicious webpage that, when visited by an authenticated AEM user, executes JavaScript in the victim's browser with their privileges. The attack requires user interaction—specifically, a victim must click a link or visit the attacker's page—but once triggered, the malicious script runs within the AEM session context, potentially allowing unauthorized actions or data theft.

  • CVE-2026-48258MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) vulnerability that allows an attacker to inject and execute malicious JavaScript code in a victim's browser. The vulnerability affects multiple versions of AEM (6.5.24, LTS SP1, 2026.04 and earlier) and requires an authenticated user with low privileges to click a specially crafted link or visit a malicious webpage. While the impact is limited to theft of session data or minor modification of page content visible to the victim, the cross-scope nature of the vulnerability means the malicious script can access resources and functionality beyond the immediate affected component.

  • CVE-2026-48264MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a DOM-based cross-site scripting vulnerability that allows an authenticated attacker to inject malicious JavaScript into a victim's browser session. The vulnerability affects multiple AEM versions up to and including 6.5.24, LTS SP1, and 2026.04. Successful exploitation requires the victim to visit an attacker-crafted webpage while logged into AEM, making social engineering a prerequisite for impact. The vulnerability carries a CVSS score of 5.4 (Medium), reflecting limited scope but meaningful exposure to confidentiality and integrity.

  • CVE-2026-48265MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a DOM-based Cross-Site Scripting vulnerability that allows authenticated attackers to inject malicious JavaScript into a victim's browser session. The flaw requires an attacker to trick a user into visiting a specially crafted webpage while logged into AEM, potentially compromising sensitive data or session integrity. Versions 6.5.24, LTS SP1, 2026.04 and earlier are affected.

  • CVE-2026-48266MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into web pages. An attacker would need to trick a user into visiting a specially crafted webpage, where the victim's browser would then execute the attacker's code in the context of their AEM session. This could allow the attacker to steal session tokens, modify page content, or perform actions on behalf of the victim. The vulnerability affects multiple versions of AEM, with scope changes that increase the potential impact surface.

  • CVE-2026-48268MEDIUM 5.4

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a DOM-based cross-site scripting (XSS) vulnerability that allows an attacker to inject and execute malicious JavaScript in a victim's browser. The attack requires the victim to visit a specially crafted webpage while authenticated to an affected AEM instance. An attacker exploiting this could steal session tokens, perform unauthorized actions, or deface content—all within the victim's authenticated session context.

  • CVE-2026-48271MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a DOM-based cross-site scripting (XSS) vulnerability that allows authenticated attackers to inject malicious JavaScript into web pages. The vulnerability requires an attacker to trick a user into visiting a specially crafted webpage while logged into AEM. Once triggered, the malicious script executes in the victim's browser with their permissions, potentially allowing session hijacking, credential theft, or unauthorized actions on behalf of the victim. The vulnerability affects AEM versions 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-48280MEDIUM 5.4

    Adobe Experience Manager contains a cross-site scripting (XSS) flaw that allows an attacker to inject malicious JavaScript into a user's browser session. The vulnerability is triggered when a victim visits a specially crafted webpage while authenticated to the affected AEM instance. Once executed, the injected code runs with the victim's privileges, potentially allowing theft of session data, unauthorized actions on their behalf, or malware distribution. The issue affects multiple AEM versions including 6.5.24, LTS SP1, and 2026.04 and earlier.

  • CVE-2026-48297MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting vulnerability that allows low-privileged users to embed malicious scripts into form fields. When legitimate users view pages containing these compromised fields, the injected JavaScript executes in their browsers, potentially compromising their sessions or enabling further attacks. The vulnerability affects AEM versions 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-48299MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged user can inject malicious JavaScript that persists in the system. When other users view the affected form, the injected script executes in their browsers, potentially stealing session data, credentials, or performing actions on their behalf. The vulnerability requires user interaction (viewing the malicious form) to trigger but can affect users across the platform due to its changed scope classification.

  • CVE-2026-48300MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows low-privileged users to inject malicious JavaScript. When a victim visits a page containing an affected form field, the attacker's script executes in their browser, potentially compromising their session or stealing sensitive data. The vulnerability affects multiple versions including 6.5.24, LTS SP1, and 2026.04 and earlier.

  • CVE-2026-48301MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows a low-privileged user to plant malicious code in form fields. When other users visit pages containing these compromised fields, the injected scripts execute in their browsers, potentially stealing session data, credentials, or performing actions on their behalf. The vulnerability affects multiple versions through 2026.04 and requires user interaction—a victim must view the poisoned form—but the attacker needs only basic authentication access to inject the payload.

  • CVE-2026-48304MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript into form fields. When other users—typically administrators or content editors—view pages containing these compromised fields, the attacker's script executes in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The vulnerability affects multiple versions through 2026.04 and requires user interaction (the victim must view the poisoned form) but can compromise users with higher privileges than the attacker.

  • CVE-2026-48559MEDIUM 5.4

    Lightweight Music Server (LMS) version 3.76.0 and earlier contains a stored cross-site scripting (XSS) vulnerability in how it handles media file metadata. An attacker can craft a malicious media file with embedded JavaScript in tags like GENRE, ARTIST, or ALBUM, then introduce it into a victim's music library. When the library is scanned, the payload is permanently stored and automatically executes in the web interface whenever that file's metadata is displayed, potentially allowing unauthorized actions on behalf of the logged-in user.

  • CVE-2026-48560MEDIUM 5.4

    Microsoft Office SharePoint contains a deserialization flaw that allows an authenticated user to manipulate data in transit, potentially impersonating other users or altering information within the SharePoint environment. The vulnerability requires valid credentials to exploit, limiting exposure to insider threats or compromised accounts rather than unauthenticated internet attackers. The impact is confined to confidentiality and integrity concerns—no system availability is at risk.

  • CVE-2026-50591MEDIUM 5.4

    Znuny, a popular open-source ticketing and service management platform, contains a stored cross-site scripting (XSS) vulnerability in its user preference settings. An authenticated attacker can inject malicious scripts into their profile preferences, which are then executed in the browsers of other users viewing that profile. This affects Znuny LTS versions before 6.5.21 and Znuny versions before 7.3.3. The vulnerability requires an attacker to have valid login credentials and user interaction (another user must visit the attacker's profile) to trigger the payload.