By weakness (CWE)

CWE-79: related vulnerabilities

CVEs classified under CWE-79. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

728 published vulnerabilities · page 4 of 8

  • CVE-2026-9107MEDIUM 6.4

    Kali Forms, a popular WordPress form-building plugin, contains a vulnerability that allows users with contributor-level permissions (or higher) to inject malicious code into pages. When other users view those pages, the injected code runs in their browsers. This affects all versions through 2.4.13. The vulnerability stems from the plugin's failure to properly clean and escape data in the 'kaliforms_field_components' parameter, a common weakness in web applications handling user input.

  • CVE-2026-9125MEDIUM 6.4

    A stored cross-site scripting (XSS) flaw exists in the Presto Player WordPress plugin affecting versions up to 4.2.0. An authenticated user with contributor-level permissions can inject malicious JavaScript code into pages by manipulating the 'link_url' parameter in the [presto_player_overlay] shortcode. Unlike reflected XSS attacks that require tricking users into clicking a link, this vulnerability persists in the database, meaning any visitor to an affected page will automatically execute the attacker's script without additional interaction. The attack relies on the plugin failing to properly validate that URLs only use safe schemes (like 'http' or 'https'), allowing attackers to sneak in 'javascript:' URIs that execute when users click overlay elements.

  • CVE-2026-9134MEDIUM 6.4

    The FooGallery WordPress plugin contains a vulnerability that allows contributors and higher-privileged users to inject malicious JavaScript code into pages. The plugin's sanitization function blocks only some HTML event handlers (like onclick and onload) but misses others like onmouseenter. When a visitor views an affected page, the injected script runs in their browser without their knowledge, potentially compromising their session or stealing information.

  • CVE-2026-9243MEDIUM 6.4

    The Plus Addons for Elementor plugin contains a flaw that allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into website pages. When a victim visits an affected page, the injected script executes in their browser, potentially compromising their session or stealing data. The vulnerability exists in the Carousel Anything widget's handling of the carousel_direction parameter and affects versions up to 6.4.15.

  • CVE-2026-9281MEDIUM 6.4

    Master Addons For Elementor, a popular WordPress plugin, contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users with author-level permissions to inject malicious scripts into pages. The vulnerability exists in the Custom JS Extension feature and affects all versions up to 3.1.0. Because the injected scripts persist in the database and execute whenever visitors view the affected pages, this could be used to steal credentials, distribute malware, or redirect users to phishing sites. The core issue is that the plugin fails to properly validate and sanitize user input when saving custom JavaScript code, and the security checks that exist only apply to the visual editor interface, not to direct API calls.

  • CVE-2026-9620MEDIUM 6.4

    The WP Latest Posts WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in versions up to 5.0.11. An authenticated attacker with author-level permissions can inject malicious scripts into post content by crafting image tags with specially formatted src attributes. Because the plugin fails to properly escape these values before displaying them, the injected scripts execute in the browsers of any visitor viewing the compromised post. This is a stored attack, meaning the payload persists in the database and affects all subsequent viewers.

  • CVE-2026-9626MEDIUM 6.4

    A stored cross-site scripting (XSS) vulnerability exists in the JSON API User plugin for WordPress affecting versions up to 4.1.0. An authenticated attacker with subscriber-level access can inject malicious scripts into post comments through the REST API's post_comment endpoint. Because the injected content bypasses moderation and is stored permanently, the malicious code executes automatically when other users view the affected page—making this a persistent threat that could compromise visitor sessions or steal sensitive information.

  • CVE-2026-9629MEDIUM 6.4

    The Canvas plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in its tag parameter that allows contributors and above to inject malicious scripts into pages. When other users view those pages, the injected scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information. The vulnerability affects all versions up to and including 2.5.2 and requires an authenticated account with at least contributor-level permissions to exploit.

  • CVE-2026-9644MEDIUM 6.4

    A WordPress plugin called LiveSmart Video Chat has a security weakness that allows authenticated users with contributor-level permissions to inject malicious code into pages. When other visitors view those pages, the injected code runs in their browsers, potentially compromising their accounts or data. The vulnerability exists in all versions up to 1.2 and stems from the plugin not properly filtering user input before displaying it on pages.

  • CVE-2026-9714MEDIUM 6.4

    A vulnerability in the Simple Divi Shortcode WordPress plugin (versions 1.2 and earlier) allows authenticated users with contributor-level permissions or higher to inject malicious code into pages. When other users view those pages, the injected code executes in their browsers. The vulnerability stems from the plugin failing to properly sanitize user input in the [showmodule] shortcode's 'id' parameter. While this requires authenticated access, the ability to execute arbitrary scripts across users' sessions creates a meaningful security risk for WordPress sites using this plugin.

  • CVE-2026-9756MEDIUM 6.4

    The GenerateBlocks WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in its Headline Block feature. An authenticated contributor can inject malicious JavaScript that persists in the database and executes whenever any site visitor—including administrators—views an affected page. The attack works by storing a JavaScript payload in the attacker's user profile, then using the plugin's 'linkMetaFieldType' attribute to create a link that triggers the malicious code. This affects all versions up to and including 2.2.1.

  • CVE-2025-65640MEDIUM 6.3

    Arket Globe Document Intelligence version 5.0.0.559 contains a reflected cross-site scripting (XSS) vulnerability in the "Task in Progress / Recent" page. An authenticated attacker can inject malicious JavaScript into document creation fields that will execute in the browsers of other users viewing that page, potentially allowing session hijacking, credential theft, or other malicious actions performed on behalf of those users.

  • CVE-2026-21768MEDIUM 6.3

    CVE-2026-21768 is a medium-severity vulnerability in the compose-rich-editor library used by HCL Verse for Android. The library does not properly validate HTML input during email composition, potentially allowing malicious content to execute. Exploitation requires local access and user interaction—an attacker must trick a user into opening a crafted email or triggering composition of malicious content on the device itself.

  • CVE-2026-25599MEDIUM 6.3

    This vulnerability affects Orca heat pump devices and their control portal. An attacker can intercept unencrypted communications between older Orca heat pumps and the control server, impersonate a legitimate device, and inject malicious code into the web portal. This injected code can steal user session cookies, compromise accounts, expose sensitive information, and grant attackers unauthorized access to the portal. The core issues are the lack of authentication, unencrypted HTTP connections, and missing input validation.

  • CVE-2026-39107MEDIUM 6.3

    Kimi AI v1.0 has a cross-site scripting (XSS) vulnerability in its Preview feature. When the AI generates code and displays it in the Preview tab, the application fails to sanitize the output properly. An attacker can embed malicious JavaScript in AI-generated responses, which then executes in a user's browser with the privileges of that session. This could allow theft of session cookies, unauthorized actions on behalf of the user, or credential harvesting.

  • CVE-2026-39451MEDIUM 6.3

    An unauthenticated Cross-Site Scripting (XSS) vulnerability exists in WP Google Review Slider version 18.0 and earlier. The flaw allows attackers to inject malicious scripts without needing to authenticate, potentially affecting site visitors and administrators. If exploited, an attacker could steal session cookies, redirect users, deface content, or perform actions on behalf of victims through their browsers.

  • CVE-2026-7299MEDIUM 6.3

    Appsmith, a low-code application development platform, contains a stored cross-site scripting (XSS) vulnerability in its SQL query editor. An authenticated developer can craft malicious database object names (table or column names) that, when rendered by the autocomplete feature, inject and execute arbitrary JavaScript in the browsers of other workspace members. This is a *persistence* risk—the malicious payload lives in the database schema itself and activates whenever a colleague accesses the same data source, potentially compromising their sessions and Appsmith workspace access.

  • CVE-2019-25731MEDIUM 6.1

    Zuz Music version 2.1 has a flaw that lets anyone send malicious code through the contact form without needing to log in. When site administrators read these messages, the injected code runs in their browsers, potentially allowing attackers to steal session data, modify settings, or trick them into performing unwanted actions. This is a persistent vulnerability, meaning the malicious payload stays stored on the server and affects every admin who views the inbox.

  • CVE-2019-25737MEDIUM 6.1

    Live Chat Unlimited version 2.8.3 contains a stored cross-site scripting (XSS) vulnerability in its chat input field. An unauthenticated attacker can inject malicious JavaScript code that persists in the system and executes when administrators access the chat interface. This allows attackers to steal admin session cookies, redirect users to phishing sites, or perform unauthorized actions within the admin dashboard without requiring authentication.

  • CVE-2025-71385MEDIUM 6.1

    Netdata versions before 2.3.1 contain a reflected cross-site scripting (XSS) vulnerability in two undocumented SVG endpoints. These endpoints (`/api/v2/ilove.svg` and `/api/v3/ilove.svg`) accept a user-supplied `love` query parameter and insert it directly into an SVG document without any sanitization. An attacker can craft a malicious URL containing JavaScript code, and when a victim visits that URL, the script executes in their browser with access to the Netdata instance's origin. Because these endpoints are accessible without authentication on default Netdata deployments, no special access is required to exploit this vulnerability.

  • CVE-2025-8591MEDIUM 6.1

    CVE-2025-8591 is a reflected cross-site scripting (XSS) vulnerability affecting multiple WSO2 products. An attacker can craft a malicious URL containing script code that, when clicked by a user, executes arbitrary JavaScript in the victim's browser. While session cookies are protected by httpOnly flags (preventing token theft), an attacker can still redirect users to phishing sites, deface page content, or harvest non-sensitive browser data. The vulnerability requires user interaction—the victim must click a crafted link—making it a social engineering vector rather than a wormable flaw.

  • CVE-2026-0279MEDIUM 6.1

    Palo Alto Networks PAN-OS contains multiple cross-site scripting (XSS) vulnerabilities in its User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN components. An unauthenticated attacker can inject malicious JavaScript that either persists in the system or executes in a user's browser. The vulnerability requires user interaction (such as clicking a malicious link) to trigger. Palo Alto's deployment best practices—restricting management interface and Authentication Portal access to trusted internal IP addresses—significantly reduce exposure.

  • CVE-2026-10510MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in the GeniexWebView component of Transsion's AI Assistant Lifestyle application for Android. An attacker can craft a malicious URL containing injected JavaScript code in the web_action_data parameter, which the vulnerable WebView will execute with the same privileges as the application. This allows arbitrary JavaScript execution in the context of the app, potentially compromising user data or enabling phishing attacks. The vulnerability affects all versions of the application currently in distribution.

  • CVE-2026-10857MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability exists in AKIN Software's E-Commerce platform versions prior to 1.25.01.06. The flaw allows an attacker to inject malicious scripts into web pages viewed by users, potentially compromising user sessions, stealing credentials, or performing unauthorized actions on behalf of the victim. The attack requires user interaction—specifically clicking a crafted link—but does not require authentication.

  • CVE-2026-11150MEDIUM 6.1

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects arbitrary scripts or HTML content that execute in the context of unrelated sites (a technique known as Universal Cross-Site Scripting or UXSS). This bypasses the same-origin policy that normally prevents one site from accessing data or performing actions on another. The vulnerability requires user interaction—a victim must visit the attacker's page—but does not require any special browser configuration or user privileges to trigger.

  • CVE-2026-11186MEDIUM 6.1

    Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in CSS handling that allows attackers to inject malicious scripts or HTML into web pages users visit. An attacker would craft a specially designed webpage that, when opened in a vulnerable version of Chrome, bypasses security boundaries and executes unauthorized code in the context of other websites. This type of attack, known as Universal XSS (UXSS), is particularly dangerous because it affects the browser itself rather than individual websites, potentially compromising user data across multiple domains.

  • CVE-2026-11273MEDIUM 6.1

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in the Omnibox (the address/search bar) that fails to properly validate user input. An attacker can craft a malicious HTML page that, when visited by a user who interacts with the Omnibox through specific UI actions, allows injection of arbitrary scripts or HTML content. This is a cross-site scripting variant (UXSS) that bypasses the normal security boundary between web pages. The attack requires user interaction and social engineering to be effective, but once triggered, can compromise the integrity and confidentiality of the browsing session.

  • CVE-2026-11392MEDIUM 6.1

    The WP Hotel Booking plugin for WordPress contains a Reflected Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can craft a specially designed link containing malicious code in the check-in or check-out date parameters. If a site user clicks that link, the injected script executes in their browser, potentially stealing credentials, session tokens, or performing actions on their behalf. This vulnerability affects all versions up to and including 2.3.1 and requires no special privileges to exploit—only user interaction.

  • CVE-2026-11603MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability exists in the Product Filter Widget for Elementor WordPress plugin through version 1.0.6. An attacker can craft a malicious link and trick a user into clicking it, causing arbitrary JavaScript to execute in the victim's browser within the context of their WordPress site. The vulnerability stems from the plugin's failure to properly sanitize user input in the 'args[filterFormArray]' parameter before displaying it back to the user. No authentication is required to exploit this flaw, and the attack is delivered silently via an admin-ajax.php endpoint without requiring verification that the request is legitimate.

  • CVE-2026-11798MEDIUM 6.1

    The Super Socializer WordPress plugin—a widely-used tool for social sharing, login, and comment features—contains a reflected cross-site scripting (XSS) vulnerability in versions up to 7.14.5. An attacker can craft a malicious link containing injected JavaScript code in the 'heateor_mastodon_share' parameter. If a user clicks that link while logged into their WordPress site, the malicious script executes in their browser with their privileges, potentially stealing session data, modifying content, or performing unauthorized actions. This requires social engineering—the attacker must trick the user into clicking—but requires no special privileges or technical user action beyond a click.

  • CVE-2026-11878MEDIUM 6.1

    OpenText Access Manager versions 5.1 through 5.1.2 contain a cross-site scripting (XSS) vulnerability in web page generation. An attacker can inject malicious JavaScript code that executes in the browsers of users accessing the affected system. The vulnerability requires user interaction (such as clicking a crafted link) but does not require authentication, making it accessible to unauthenticated threat actors. While not currently listed in CISA's Known Exploited Vulnerabilities catalog, the combination of network accessibility and user-triggered execution means organizations should prioritize remediation.

  • CVE-2026-12137MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability exists in the SysBasics Customize My Account for WooCommerce plugin for WordPress. The flaw is in how the plugin handles the 'tab' parameter—it fails to properly sanitize and escape user input before displaying it on the admin dashboard. An attacker can craft a malicious link containing JavaScript code that executes in the browser of any logged-in Shop Manager or administrator who clicks it. The attack requires social engineering (tricking a user into clicking a link) and a valid WordPress admin session, but poses a real risk to compromised user accounts or credential-based attacks.

  • CVE-2026-12425MEDIUM 6.1

    PowerSchool Employee Access Center version 23.10 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into login URLs. When a user clicks a crafted link, the injected code executes in their browser with their privileges, potentially enabling session hijacking, credential theft, or unauthorized actions on their behalf.

  • CVE-2026-12459MEDIUM 6.1

    Google Chrome versions prior to 149.0.7827.155 contain a vulnerability in the Serial component that allows attackers to inject malicious scripts or HTML into web pages through a specially crafted HTML file. The attack requires user interaction (clicking or otherwise engaging with the malicious page) but does not require the victim to have special privileges. The injected content can compromise page integrity and access sensitive user data within the affected browser context.

  • CVE-2026-12754MEDIUM 6.1

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 1.8.12. An attacker can craft a malicious link containing JavaScript code in the 'layoutstyle' parameter. If a user clicks that link while viewing a page with the vulnerable [vikbooking view="roomslist"] shortcode, the attacker's script executes in the user's browser in the context of that website. This could allow credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (clicking a link) and only affects pages that use the specific shortcode.

  • CVE-2026-13015MEDIUM 6.1

    The Wp Google Places Review Slider plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions 18.1 and earlier. An attacker can craft a malicious link containing JavaScript code in the 'place' parameter. When a site administrator or authorized user clicks this link, the injected script executes in their browser within the context of the WordPress admin panel, potentially allowing the attacker to steal credentials, modify site content, or perform other unauthorized actions on behalf of the victim.

  • CVE-2026-13245MEDIUM 6.1

    The MaxButtons – Create buttons plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 9.8.5. An attacker can craft a malicious link containing JavaScript code that executes in a victim's browser when they click it. Because the plugin doesn't properly sanitize the 'view' parameter, the injected script runs in the context of the WordPress site, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on behalf of the victim. This requires social engineering—the attacker must trick someone into clicking a crafted link—but no user authentication is needed to create the attack.

  • CVE-2026-13334MEDIUM 6.1

    The Mang Board plugin for WordPress has a flaw that allows attackers to inject malicious code into web pages. An unauthenticated attacker can craft a deceptive link containing malicious script in the 'stag' parameter. When a user clicks the link, the injected script runs in their browser, potentially stealing session cookies, credentials, or performing actions on their behalf. The vulnerability affects all versions up to 2.3.4.

  • CVE-2026-13836MEDIUM 6.1

    Google Chrome versions before 150.0.7871.47 contain a CSS handling flaw that allows attackers to inject malicious scripts or HTML into pages you visit. An attacker would craft a deceptive webpage and trick you into opening it; the browser's CSS parser would then execute the attacker's code in the context of a legitimate site you trust. This is a 'universal cross-site scripting' (UXSS) vulnerability—more severe than typical XSS because it bypasses the normal boundaries between websites.

  • CVE-2026-14000MEDIUM 6.1

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects unauthorized scripts or HTML content that executes with the privileges of the current webpage—a technique known as Unintended Cross-Site Scripting (UXSS). This allows attackers to steal data, manipulate page content, or perform actions on behalf of the user without additional user interaction beyond viewing the page.

  • CVE-2026-14001MEDIUM 6.1

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles network-related content that allows attackers to inject malicious scripts or HTML code into web pages you visit. An attacker would craft a specially designed webpage; when you visit it, the injected code runs in your browser with the privileges of the website you're viewing, potentially stealing data or performing actions on your behalf. This type of attack, known as UXSS (Universal XSS), bypasses Chrome's normal security boundaries.

  • CVE-2026-14068MEDIUM 6.1

    Google Chrome on iOS contains a flaw in how it handles the Omnibox (address bar) that can allow an attacker to inject malicious scripts or HTML content into a webpage you're viewing. The vulnerability requires a user to perform specific gestures in the browser interface—such as interacting with the address bar in a particular way—after visiting a specially crafted webpage. This is a cross-site scripting variant (UXSS) that affects Chrome versions before 150.0.7871.47 on iOS devices.

  • CVE-2026-14145MEDIUM 6.1

    Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in how CSS (Cascading Style Sheets) is processed that allows attackers to inject malicious scripts or HTML content into web pages. An attacker would need to trick a user into visiting a specially crafted webpage; if successful, the injected code runs with the privileges of the visited site, potentially compromising user data or enabling further attacks. This is classified as a Universal XSS (UXSS) vulnerability, meaning the attack bypasses normal browser security boundaries.

  • CVE-2026-14147MEDIUM 6.1

    Google Chrome versions before 150.0.7871.47 contain a flaw in CSS handling that allows an attacker to inject malicious scripts or HTML into web pages viewed by users. The vulnerability requires user interaction (clicking a link or visiting a crafted page) and affects the security boundary between websites, potentially allowing one site to compromise another or steal sensitive data. While Chromium classified this as low severity internally, the cross-site nature of the exploit and the ease of triggering it via a simple crafted HTML page elevate the practical risk.

  • CVE-2026-14358MEDIUM 6.1

    The Wikimedia Foundation's MediaWiki Charts Extension contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can craft a specially designed chart parameter or input that, when processed by the extension, executes arbitrary JavaScript in the browsers of users viewing that content. This requires user interaction—specifically, a user must view the affected page—but does not require authentication. The vulnerability affects multiple version branches of the Charts Extension and has been patched in versions 1.43.9, 1.44.6, and 1.45.4.

  • CVE-2026-1450MEDIUM 6.1

    The rognone WordPress plugin contains a reflected cross-site scripting (XSS) flaw that allows unauthenticated attackers to inject malicious scripts into web pages. The vulnerability exists in how the plugin handles the 'mode' parameter—it fails to properly sanitize user input and escape output, creating an opening for attackers to craft malicious links. If a user clicks such a link while using a site running the vulnerable plugin, the attacker's script executes in their browser with access to session data and sensitive information.

  • CVE-2026-1451MEDIUM 6.1

    The rognone plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into pages viewed by unsuspecting users. An attacker could craft a malicious link containing JavaScript in the 'a' parameter and trick a user into clicking it, causing the script to execute in their browser within the context of the WordPress site. This works because the plugin fails to properly sanitize user input or escape output before displaying it. The vulnerability affects versions up to and including 0.6.2.

  • CVE-2026-15127MEDIUM 6.1

    A flaw in how Google Chrome handles WebGL—a web technology for rendering graphics—allows attackers to inject malicious scripts or HTML into pages you visit. An attacker could craft a deceptive webpage that, when opened in a vulnerable Chrome browser, executes unauthorized code with the privileges of the web page you're viewing. This is a form of cross-site scripting (XSS) attack. The vulnerability affects Chrome versions prior to 150.0.7871.115.

  • CVE-2026-15128MEDIUM 6.1

    A flaw in how Google Chrome handles web forms before version 150.0.7871.115 allows attackers to inject malicious scripts or HTML into pages viewed by users. An attacker would craft a specially designed webpage and trick a user into visiting it, at which point the injected code runs in the user's browser with access to sensitive page content. This is a cross-site scripting (XSS) variant that bypasses normal browser protections.

  • CVE-2026-15297MEDIUM 6.1

    The Brevo email marketing plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability in versions up to 3.1.77. An attacker can craft a malicious link containing injected scripts that execute in a victim's browser if the victim clicks the link while logged into WordPress. The vulnerability stems from the plugin's failure to properly sanitize and escape user input in the 'page' parameter. No authentication is required to exploit this, and the attack relies on social engineering—tricking a user into clicking a malicious link.

  • CVE-2026-20233MEDIUM 6.1

    Cisco Webex Meetings contained a cross-site scripting (XSS) vulnerability in its web interface that could allow an attacker to inject malicious scripts if a user clicked a crafted link. The vulnerability resulted from weak input validation. Cisco has already patched the service, and users do not need to take action—the fix has been deployed automatically.

  • CVE-2026-21825MEDIUM 6.1

    HCL Digital Experience and Digital Experience Compose contain a reflected cross-site scripting (XSS) vulnerability in their search center functionality. An attacker can craft a malicious link containing JavaScript code and trick a user into clicking it. When the victim visits the link, the attacker's script executes in their browser with their privileges, potentially stealing session cookies, credentials, or performing actions on their behalf. This vulnerability requires user interaction—the victim must click a malicious link—which somewhat limits its reach, but the ability to target any user makes it a meaningful risk for organizations relying on these platforms.

  • CVE-2026-2425MEDIUM 6.1

    The hiWeb Migration Simple WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in how it handles the 'new_domain' parameter. An attacker can craft a malicious link and trick a WordPress administrator into clicking it, causing arbitrary JavaScript to execute in the admin's browser session. This could allow the attacker to steal session tokens, modify site content, or perform administrative actions on behalf of the compromised admin. The vulnerability affects all versions through 2.0.0.1.

  • CVE-2026-25860MEDIUM 6.1

    OpenClinic GA version 5.351.19 contains a reflected cross-site scripting (XSS) vulnerability in its DICOM image upload functionality. An attacker can craft a malicious DICOM medical image file containing JavaScript code in metadata fields like Study Description. When a user uploads and processes this file through the application's DICOM upload feature, the embedded script executes in their browser without restriction, potentially allowing the attacker to steal session cookies, redirect users to malicious sites, or perform unauthorized actions on behalf of the victim.

  • CVE-2026-29170MEDIUM 6.1

    Apache HTTP Server versions 2.4.67 and earlier contain a cross-site scripting (XSS) vulnerability in the mod_proxy_ftp module. When the server is configured to proxy FTP directory listings—whether forwarding traffic to an upstream FTP server or presenting one via reverse proxy—it fails to properly sanitize HTML generated for directory contents. An attacker can craft malicious FTP directory entries or filenames containing JavaScript code. When an administrator or user views the directory listing in a browser, the malicious script executes in their session, potentially allowing session hijacking, credential theft, or administrative actions.

  • CVE-2026-30586MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in usememos Memos version 0.26.0 that allows an attacker to inject malicious code into memo pages. When a user views a compromised memo—whether public or private—the attacker's script executes in the user's browser, potentially exposing sensitive information. The vulnerability stems from improper sanitization of user input in the memo rendering component, meaning the application fails to adequately strip or encode dangerous HTML and JavaScript before displaying memo content.

  • CVE-2026-32856MEDIUM 6.1

    Ellucian Banner Self-Service is vulnerable to a reflected cross-site scripting (XSS) attack before its April T2 2025 release. An attacker can craft a malicious URL and send it to an unauthenticated user. When clicked, the URL injects malicious JavaScript into the victim's browser through an unsanitized parameter in the dateConverter endpoint. This could allow the attacker to steal session cookies, hijack accounts, or perform actions on behalf of the victim.

  • CVE-2026-33553MEDIUM 6.1

    Northern.tech CFEngine Enterprise contains a cross-site scripting (XSS) vulnerability in versions 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1. An attacker can inject malicious scripts that execute in the browser context of users interacting with the CFEngine Enterprise interface, potentially compromising user sessions or stealing sensitive information without requiring authentication.

  • CVE-2026-34416MEDIUM 6.1

    OSCAL-GUI contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to execute malicious JavaScript in users' browsers without authentication. An attacker crafts a deceptive URL containing specially crafted input in the project request parameter. When a victim clicks the link, the malicious payload executes in their browser, bypassing security filters. This attack requires social engineering—tricking someone into clicking a malicious link—but the impact can include session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

  • CVE-2026-34417MEDIUM 6.1

    OSCAL-GUI contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into a victim's browser. An unauthenticated attacker can craft a malicious URL containing JavaScript code in the project request parameter. When a victim visits this URL, the injected code executes in their browser with the same privileges as the victim, potentially allowing attackers to steal session cookies, perform actions on behalf of the user, or redirect them to phishing sites. The vulnerability requires user interaction—specifically clicking a malicious link—but no authentication is required to exploit it.

  • CVE-2026-34915MEDIUM 6.1

    Revive Adserver versions up to 6.0.6 contain a vulnerability in the zone-include.php script where user input is not properly validated before being used in database queries. An attacker with low privileges can manipulate the clientid parameter to inject malicious SQL commands, potentially reading or modifying sensitive data in the database. The attack does not require special access rights and is triggered via a web request, though user interaction is needed for successful exploitation.

  • CVE-2026-35212MEDIUM 6.1

    OpenCTI, an open-source threat intelligence platform, contains a cross-site scripting (XSS) vulnerability in how it renders email message data. An attacker can craft a malicious email observable with unsanitized content in the message body, which executes JavaScript in a victim's browser when they view it. Because threat intelligence is often shared across teams via STIX files or automated ingesters, this could be weaponized to steal session cookies at scale, potentially compromising multiple analysts' accounts. The vulnerability requires user interaction—someone must view the crafted email observable—but the attack surface is broad given how threat intelligence is typically distributed.

  • CVE-2026-36324MEDIUM 6.1

    SourceCodester Doctor Appointment System version 1.0 contains a Cross-Site Scripting (XSS) vulnerability in its user registration form. An attacker can inject malicious scripts into the registration page, which are then executed in the browsers of other users who view that registration data. This allows the attacker to steal session cookies, redirect users to phishing sites, or perform actions on behalf of legitimate users without their knowledge.

  • CVE-2026-36521MEDIUM 6.1

    PublicCMS V5.202506.d contains a cross-site scripting (XSS) vulnerability in its site configuration management module. An attacker can inject malicious scripts into the configuration interface, which are then executed in the browsers of administrators and other users who view the affected settings. This allows attackers to steal session tokens, redirect users to phishing sites, or perform unauthorized administrative actions without requiring authentication to the CMS itself.

  • CVE-2026-36725MEDIUM 6.1

    FastapiAdmin version 2.2.0 contains a vulnerability where attackers can inject malicious scripts into system notices. When an administrator or authorized user views a crafted notice through the notice creation endpoint, the injected code executes in their browser, potentially allowing attackers to steal session tokens, modify page content, or perform actions on their behalf. The attack requires user interaction—the victim must view the malicious notice—but no authentication is needed to craft and inject the payload.

  • CVE-2026-37216MEDIUM 6.1

    Ruoyi version 4.8.2 contains a cross-site scripting (XSS) vulnerability in its system notice creation interface. An attacker can inject malicious JavaScript code through the /system/notice/add endpoint, which will execute in the browsers of users who view the crafted notice. This vulnerability requires user interaction—specifically, a victim must view a notice containing the malicious payload—but does not require authentication to create the notice. The impact is limited to information disclosure and minor modifications visible to end-users; system availability is not affected.

  • CVE-2026-38579MEDIUM 6.1

    Damasac Thaipalliative LTE through version 3.0 contains multiple reflected cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts into web pages viewed by users. The flaws exist in the /substudy/ezform.php file where user-supplied values are directly inserted into HTML without proper sanitization. An attacker can craft a malicious URL and trick a user into clicking it, causing arbitrary JavaScript to execute in that user's browser within the context of the vulnerable application.

  • CVE-2026-39897MEDIUM 6.1

    Cacti, an open-source monitoring and performance management platform, contains a reflected cross-site scripting (XSS) vulnerability in its authentication footer component. An attacker can craft a malicious link that, when clicked by a user, injects arbitrary JavaScript into the victim's browser session. This could allow theft of session cookies, credential harvesting, or redirection to phishing sites. The vulnerability affects Cacti versions 1.2.30 and earlier; version 1.2.31 and later contain the fix.

  • CVE-2026-39900MEDIUM 6.1

    Cacti, a widely-used open source tool for monitoring network performance and managing faults, has a reflected cross-site scripting (XSS) vulnerability in its auth_profile.php file. An attacker can craft a malicious link containing JavaScript code in the 'tab' parameter that executes in a victim's browser when they click it. The victim must be tricked into clicking the link, but once they do, the attacker gains the ability to steal session tokens, alter page content, or perform actions on behalf of the logged-in user. Cacti versions 1.2.30 and earlier are vulnerable; version 1.2.31 fixes the issue.

  • CVE-2026-41539MEDIUM 6.1

    QNAP has patched a cross-site scripting (XSS) vulnerability affecting multiple versions of QTS and QuTS hero operating systems. The flaw allows remote attackers to inject malicious scripts that execute in users' browsers, potentially bypassing security controls or stealing sensitive application data. No authentication is required to attempt exploitation, but a user must be tricked into clicking a malicious link or visiting a compromised page. QNAP has released security updates addressing the issue across affected product lines.

  • CVE-2026-42253MEDIUM 6.1

    Apache ActiveMQ's web console contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious content into HTTP response headers. The flaw exists in how the MessageServlet handles JMS message properties—it copies them directly into HTTP headers without filtering or validation. An attacker who can craft a JMS message with specially crafted properties could inject security headers, potentially leading to session hijacking, credential theft, or malware delivery when a user views the affected web console. The vulnerability requires user interaction (a victim must view the injected content) and affects versions of ActiveMQ and ActiveMQ Web released before 5.19.7 and 6.2.6.

  • CVE-2026-42573MEDIUM 6.1

    Svelte, a lightweight and performance-focused web framework, contained a vulnerability in versions before 5.55.7 that allowed attackers to manipulate the browser's DOM in a way that corrupted Svelte's internal state. By exploiting DOM clobbering—a technique where attackers inject HTML elements that shadow legitimate JavaScript objects—an attacker could potentially inject malicious scripts that execute in a user's browser, leading to cross-site scripting (XSS) attacks. The vulnerability requires user interaction, such as clicking a link or visiting a malicious page, to be triggered.

  • CVE-2026-42599MEDIUM 6.1

    Svelte, a popular web framework, contains a vulnerability where untrusted data rendered as HTML attributes can include malicious event handlers. If your application uses Svelte's spread syntax to render attributes from user input or external sources, attackers could inject code that runs when users interact with those elements. The risk is reduced if Svelte's hydration process completes before the injected event fires, but this shouldn't be relied upon as a defense. Version 5.55.7 and later address this issue.

  • CVE-2026-4322MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability has been discovered in Destekz, a web design and digital advertising platform used by Raera, an Ankara-based agency. The flaw allows attackers to inject malicious scripts into web pages viewed by users. When a victim clicks a specially crafted link, the attacker's code runs in their browser with access to sensitive information like session cookies or personal data. Importantly, the vendor has confirmed the product is no longer supported, meaning no patches will be issued.

  • CVE-2026-44644MEDIUM 6.1

    LiquidJS, a popular template engine used in Shopify and GitHub Pages, contains a cross-site scripting (XSS) vulnerability in its strip_html filter. This filter is meant to sanitize HTML by removing tags before rendering, but a flaw in its regex pattern allows attackers to bypass it by embedding newline characters within HTML tags. Because browsers treat newlines as whitespace inside tags, malicious event handlers like onerror or onload still execute. Versions 10.25.7 and earlier are affected. The vulnerability requires an attacker to control the input rendered through the vulnerable filter and assumes the application does not separately escape HTML output.

  • CVE-2026-44746MEDIUM 6.1

    SAP NetWeaver JAVA contains a reflected cross-site scripting (XSS) vulnerability in its JDBC Test Servlet component. An attacker can craft a malicious URL containing embedded script code. When an unsuspecting user clicks this link, the script executes in their browser within the context of the affected application. This allows the attacker to steal session data, modify information displayed to the user, or perform unauthorized actions on behalf of the victim—all without requiring the attacker to authenticate or exploit a server-side flaw. The vulnerability requires user interaction (clicking a link) to be triggered.

  • CVE-2026-45500MEDIUM 6.1

    Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages served by the application. An attacker can exploit this by crafting a malicious link or embedding code in a page that, when visited by a user, executes arbitrary actions in that user's browser session—such as stealing credentials, impersonating the user, or modifying email content. The vulnerability requires user interaction (clicking a link or visiting a page) but can affect any Exchange Server deployment exposed to the internet or accessible via webmail interfaces.

  • CVE-2026-45560MEDIUM 6.1

    Roxy-WI, a web-based management console for load balancers and web servers, contains a stored cross-site scripting (XSS) vulnerability in its log viewer. The vulnerability exists because the application builds HTML pages by concatenating user-controlled log data without sanitization. An attacker who can generate traffic through a managed load balancer—such as by making HTTP requests to a public-facing application—can inject malicious scripts into access logs. When an administrator opens the log viewer in Roxy-WI, the injected payload executes in their browser with the privileges of that user. This is a supply-chain risk: any internet-facing service behind a Roxy-WI-managed load balancer becomes a potential injection point.

  • CVE-2026-46547MEDIUM 6.1

    NocoDB, a popular no-code platform for building databases with a spreadsheet-like interface, contains a reflected cross-site scripting (XSS) vulnerability in its Page Leaving Warning feature. Attackers can craft malicious URLs containing JavaScript code that execute in a victim's browser when they click a specially crafted link or are redirected to the warning page. The vulnerability affects versions prior to 2026.04.1 and requires user interaction—specifically clicking a malicious link—to trigger the attack.

  • CVE-2026-46642MEDIUM 6.1

    draw.io versions before 29.7.12 contain a stored cross-site scripting (XSS) vulnerability triggered when a crafted diagram file (.drawio) is opened. A malicious diagram can embed JavaScript code disguised as image markup that executes in the editor's security context as soon as the file is imported. The vulnerability stems not from the display rendering logic—which properly sanitizes content—but from a feature-detection routine in the Text Format panel that reads raw cell labels and inserts them into the DOM without validation. Attackers can craft and distribute poisoned diagram files that execute arbitrary scripts when opened by a user.

  • CVE-2026-48157MEDIUM 6.1

    Slim, a popular PHP web framework, contains a vulnerability in versions 4.4.0 through 4.15 where developers can inadvertently create reflected cross-site scripting (XSS) vulnerabilities. If an application passes user-supplied data (like a search query or request parameter) into the HttpException::setTitle() or setDescription() methods, that data will be rendered without HTML escaping when an error page is displayed to the user. An attacker could craft a malicious request containing JavaScript that executes in the victim's browser. The vulnerability exists even when error detail display is disabled. The issue is fixed in Slim 4.15.2.

  • CVE-2026-48942MEDIUM 6.1

    CVE-2026-48942 is a cross-site scripting (XSS) vulnerability in JoomlaWorks K2 version 2.26 and earlier. The vulnerability exists because user profile images are inserted directly into HTML without proper sanitization. An attacker who can upload or modify a user profile image can craft a malicious image filename or source that executes JavaScript in the browsers of anyone viewing that profile. This requires user interaction (clicking or viewing a profile page) and affects only the user's current browser session and site context, but could be used to steal session cookies, redirect users, or deface content.

  • CVE-2026-48949MEDIUM 6.1

    A Joomla vulnerability allows attackers to inject malicious scripts into multi-factor authentication (MFA) management pages. Because user input isn't properly validated before being displayed, an attacker can craft a malicious link that, when clicked by an authenticated administrator, executes JavaScript in their browser context. This could allow theft of session tokens, modification of MFA settings, or other administrative actions performed without the victim's knowledge.

  • CVE-2026-48950MEDIUM 6.1

    CVE-2026-48950 is a cross-site scripting (XSS) vulnerability in Joomla's template file management component (com_templates). An attacker can inject malicious scripts into file names or metadata that are displayed without proper sanitization, allowing them to steal session cookies, redirect users, or perform actions on behalf of an administrator viewing the file management interface. The vulnerability requires user interaction—specifically, an administrator must visit the vulnerable page—but affects the security of the entire Joomla installation.

  • CVE-2026-48951MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in Joomla due to insufficient escaping of user input in modal return layouts across various components. An attacker can craft a malicious link or form that, when clicked by an authenticated or unauthenticated user, injects arbitrary JavaScript into the page. This script executes in the victim's browser within the context of the Joomla site, potentially allowing theft of session tokens, credential harvesting, or malware distribution.

  • CVE-2026-48952MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in Joomla's installer component update list view. The vulnerability arises from insufficient sanitization of user-supplied input, allowing an attacker to inject malicious scripts that execute in the context of an administrator's browser session. An authenticated or unauthenticated attacker can craft a malicious link containing JavaScript code; when an admin clicks it and accesses the installer update list, the injected script runs with the privileges of that administrator account. This could lead to unauthorized actions, session hijacking, or further compromise of the Joomla installation.

  • CVE-2026-48953MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in Joomla's generic image output layout due to insufficient output escaping. An attacker can craft a malicious link containing JavaScript code that executes in a victim's browser when they view or interact with image content. The vulnerability requires user interaction and affects the confidentiality and integrity of user sessions, though it does not impact availability.

  • CVE-2026-48954MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability has been discovered in Joomla's language override feature. The vulnerability stems from inadequate input validation, allowing an attacker to inject malicious scripts that execute in users' browsers. An attacker would need to trick a user into visiting a specially crafted link or interacting with a compromised page, but no special privileges are required to exploit this flaw. The vulnerability affects the confidentiality and integrity of user sessions and data, though it does not directly impact system availability.

  • CVE-2026-49294MEDIUM 6.1

    Valhalla, an open-source routing engine for OpenStreetMap data, contains a cross-site scripting (XSS) vulnerability in versions 3.6.3 and earlier. The flaw exists in how the application handles JSONP callback parameters—user-supplied values are reflected directly into responses without filtering or encoding. An attacker can inject malicious JavaScript by crafting a specially formatted URL; if a victim clicks or loads that URL, the attacker's script runs in the victim's browser with the same privileges as legitimate requests, potentially allowing theft of session tokens, credential capture, or unauthorized actions. This is a reflected XSS vulnerability requiring user interaction but with relatively broad impact potential.

  • CVE-2026-49375MEDIUM 6.1

    JetBrains TeamCity versions before 2026.1 and 2025.11.5 contain a reflected cross-site scripting (XSS) vulnerability on the repository download page. An attacker can craft a malicious URL and trick a user into clicking it, allowing the attacker to steal session cookies, perform actions on behalf of the user, or redirect them to phishing sites. The vulnerability requires user interaction and does not directly compromise the server itself.

  • CVE-2026-49384MEDIUM 6.1

    JetBrains PyCharm versions prior to 2025.3.4 contain a stored cross-site scripting (XSS) vulnerability in Jupyter notebook Markdown cells. An attacker can inject malicious scripts into Markdown content within a notebook, which are then executed in the browser context of users who view the notebook. This allows for session hijacking, credential theft, or malware distribution without requiring the victim to take any action beyond opening an affected notebook.

  • CVE-2026-50040MEDIUM 6.1

    Storage Concentrator (SC and SCVM) contains a reflected cross-site scripting (XSS) vulnerability in its 404 error page handling. When a user visits a specially crafted malicious link, unsanitized content is echoed back and executed as JavaScript in their browser. An attacker can exploit this to steal session credentials, redirect users to phishing sites, or perform actions within the application while impersonating the victim—but only if the victim clicks a malicious link while already logged in.

  • CVE-2026-50133MEDIUM 6.1

    Hugo, a popular static site generator, contains a stored cross-site scripting (XSS) vulnerability in versions prior to 0.162.0. When Hugo processes HTML content files—either .html files placed in the /content directory or content generated by adapters configured with text/html media type—it outputs the body verbatim without sanitization. An attacker who can inject malicious HTML into a site's content pipeline can embed JavaScript that executes in visitors' browsers. This is particularly dangerous for sites that accept HTML content from external or user-controlled sources.

  • CVE-2026-50230MEDIUM 6.1

    Lyrion Music Server version 9.2.0 has a cross-site scripting (XSS) vulnerability in its server logging endpoint. An attacker can craft a malicious URL containing JavaScript code and trick a user into clicking it. When the user visits the link, the JavaScript runs in their browser with the same permissions as the Lyrion application, potentially allowing the attacker to steal session cookies, redirect the user, or perform actions on their behalf. No authentication is required to exploit this vulnerability, making it accessible to anyone who can send a link to a target user.

  • CVE-2026-50235MEDIUM 6.1

    Lyrion Music Server 9.2.0 has a reflected cross-site scripting (XSS) vulnerability in its advanced search feature. An attacker can craft a malicious link containing JavaScript code in the search parameters. When a user clicks the link or is tricked into visiting it, the malicious script executes in their browser, potentially allowing the attacker to steal session cookies, hijack accounts, or perform actions on behalf of the user. The vulnerability requires user interaction—the victim must click a malicious link—but no special privileges or complex setup are needed to exploit it.

  • CVE-2026-50555MEDIUM 6.1

    Angular's server-side rendering (SSR) feature includes a vulnerability in how it handles the serialization of raw-text HTML elements like <script>, <style>, and <iframe> tags. When dynamic content containing certain Unicode characters (specifically astral characters like emojis) appears before a closing tag, the server fails to properly escape that closing tag. This allows an attacker to break out of the raw-text context and inject arbitrary JavaScript that executes in the victim's browser with the same origin privileges. The flaw affects Angular versions prior to specific patched releases and requires user interaction (such as clicking a link) to exploit.

  • CVE-2026-50556MEDIUM 6.1

    Angular applications using Server-Side Rendering (SSR) are vulnerable to Cross-Site Scripting attacks when dynamic text is bound inside <noscript> elements. The vulnerability stems from a gap in how the underlying DOM emulation library (domino) escapes closing tags during HTML serialization. An attacker who can control content rendered within a <noscript> element can inject a closing tag that terminates the noscript block prematurely, allowing arbitrary JavaScript to execute in the user's browser with the application's privileges. The issue affects Angular versions prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25.

  • CVE-2026-50557MEDIUM 6.1

    Angular versions prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.22 contain a template sanitization bypass vulnerability that allows attackers to inject malicious scripts through specially crafted namespace-based HTML elements. By using namespaced variants like <svg:script> or <:svg:script>, attackers can circumvent Angular's built-in protections against script injection, potentially leading to cross-site scripting (XSS) attacks. The vulnerability also extends to namespaced attributes in SVG and MathML elements, which can bypass attribute sanitizers. Any application using a vulnerable Angular version that processes user-supplied or dynamically rendered templates is at risk.

  • CVE-2026-50745MEDIUM 6.1

    A cross-site scripting vulnerability exists in Revive Adserver's stats-video.php script. The application fails to properly sanitize and encode user-supplied input before displaying it back to visitors. An attacker could craft a malicious link that, when clicked by a user, executes arbitrary JavaScript in the context of the affected domain. This is a reflected XSS vulnerability—the payload doesn't persist on the server, but requires social engineering to trick a user into clicking a specially crafted URL.

  • CVE-2026-50765MEDIUM 6.1

    Koha Library Management System contains a stored cross-site scripting (XSS) vulnerability in its patron restriction type administration interface. An authenticated administrator can inject malicious JavaScript into restriction type labels, which is then stored and executed in the browsers of other users who view that page. This allows an insider threat to compromise other administrators' sessions or steal sensitive library data without requiring additional user interaction beyond normal administrative activities.