Filtered by CWE-79
Total 47114 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-40986 2 Broadcom, Spring 2 Spring Web Flow, Spring Web Flow 2026-09-04 4.8 Medium
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
CVE-2026-85541 1 Interinfo 1 Dreammaker 2026-09-04 5.4 Medium
DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.
CVE-2026-85405 1 Eleveo 1 Call Recording Software 2026-09-04 3.5 Low
A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument name/username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-35497 1 Trimble 1 Tm4web 2026-09-04 N/A
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.
CVE-2026-81282 2 Villatheme, Wordpress 2 Product Variations Swatches For Woocommerce, Wordpress 2026-09-04 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
CVE-2026-81292 2 Ido Kobelkowsky, Wordpress 2 Simple Payment, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
CVE-2026-81300 2 Silverplugins217, Wordpress 2 Calculation For Contact Form 7, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
CVE-2026-81776 2 Advanpix, Wordpress 2 Wp Quicklatex, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
CVE-2026-84765 2 John Havlik, Wordpress 2 Breadcrumb Navxt, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
CVE-2026-84773 2 Wordpress, 作者 2 Wordpress, Shane Bishop:ewww Image Optimizer 2026-09-04 7.2 High
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
CVE-2026-14466 1 Stormshield 1 Stormshield Network Security 2026-09-04 4.3 Medium
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.
CVE-2026-84848 2 Brightvesseldev, Wordpress 2 Quick Event Manager, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
CVE-2026-85453 1 Themoos 1 Core-moos 2026-09-04 6.1 Medium
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
CVE-2026-18957 1 Menulux 1 Menulux Portal 2026-09-04 5.4 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: before 20260903211448.
CVE-2026-73781 2 Hewlett Packard Enterprise (hpe), Hpe 157 Aos-cx, Aruba Cx 10000-48y6c \(r8p13a\), Aruba Cx 10000-48y6c \(r8p14a\) and 154 more 2026-09-04 8.4 High
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
CVE-2026-85600 1 Getgrav 1 Grav 2026-09-04 5.4 Medium
Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username validation (DataUser::isValidUsername) blocks filesystem-dangerous characters but not <, >, ", or ', allowing an attacker to register a username containing an HTML payload. When an administrator views a UI surface that renders the username through tHtml()—such as the two-factor force-disable confirmation prompt or the 'page is locked' editor notice—the payload executes in their authenticated session. Fixed in 2.0.21.
CVE-2026-85598 1 Getgrav 1 Grav 2026-09-04 6.4 Medium
Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.
CVE-2026-85593 1 Phpmyfaq 1 Phpmyfaq 2026-09-04 5.4 Medium
phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject JavaScript payloads that execute in the browsers of all users viewing the affected FAQ pages.
CVE-2026-84370 1 Svg 1 Svgo 2026-09-04 8.2 High
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href values, and it does not remove ASCII tab, line-feed, or carriage-return characters before checking URL schemes. Browsers remove those characters before parsing a scheme, allowing an executable link to pass the plugin's check. When an application processes attacker-controlled SVG input and serves the result in an active browser context, a victim who activates the surviving link can execute script in the SVG's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.
CVE-2026-84189 1 Librenms 1 Librenms 2026-09-04 8.1 High
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0.