Total
47117 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16260 | 2026-08-23 | 6.8 Medium | ||
| The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item. | ||||
| CVE-2026-78059 | 1 Sourcecodester | 1 Stock Management System | 2026-08-23 | 4.3 Medium |
| A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-78055 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-08-23 | 4.3 Medium |
| A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-31803 | 1 Combodo | 1 Itop | 2026-08-21 | 8 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-31880 | 1 Combodo | 1 Itop | 2026-08-21 | 8 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-55087 | 1 Etherpad | 1 Etherpad | 2026-08-21 | 6.1 Medium |
| Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary: x-proxy-path, or Cache-Control: private, no-store. A shared proxy or CDN can cache the resulting response and serve attacker-injected script to an administrator. In src/node/hooks/express/specialpages.ts, version 3.0.0 also accepts a protocol-relative x-proxy-path value when constructing the /p/:pad/timeslider redirect, allowing redirection to an attacker-controlled host. The issues are exploitable when the deployment permits client-supplied x-proxy-path headers to reach Etherpad. This issue is fixed in version 3.1.0. | ||||
| CVE-2026-30826 | 1 Combodo | 1 Itop | 2026-08-21 | 8 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-30819 | 1 Combodo | 1 Itop | 2026-08-21 | 7.3 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-74800 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-08-21 | 9 Critical |
| SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link. | ||||
| CVE-2026-13202 | 1 Opentext | 1 Directory Services | 2026-08-21 | N/A |
| A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | ||||
| CVE-2026-33437 | 1 Stirling | 1 Stirling Pdf | 2026-08-21 | 8.1 High |
| Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in version 2.0.0. | ||||
| CVE-2026-63670 | 1 Apostrophecms | 1 Apostrophecms | 2026-08-21 | 6.1 Medium |
| ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6. | ||||
| CVE-2026-52606 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php. | ||||
| CVE-2026-52609 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | ||||
| CVE-2026-74902 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-08-21 | 8.6 High |
| SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor. | ||||
| CVE-2026-74252 | 1 J2commerce.com | 1 J2store Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name. | ||||
| CVE-2026-27365 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-08-21 | 5.9 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | ||||
| CVE-2026-18371 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | ||||
| CVE-2026-18372 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. | ||||
| CVE-2026-66581 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||