Total
47224 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-6864 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link. | |||||
| CVE-2026-42506 | 1 Golang | 1 Net | 2026-07-23 | N/A | 6.1 MEDIUM |
| Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |||||
| CVE-2026-40598 | 2026-07-23 | N/A | N/A | ||
| Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2. | |||||
| CVE-2026-48229 | 2026-07-23 | N/A | 5.4 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into HTML form hidden input value attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered. | |||||
| CVE-2026-9104 | 2026-07-23 | N/A | 6.4 MEDIUM | ||
| The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The unescaped injection path is triggered specifically when the viewing user lacks edit capabilities, meaning payloads embedded in draft post titles via attribute-breakout techniques execute for unauthenticated users and subscribers. | |||||
| CVE-2026-39970 | 2026-07-23 | N/A | N/A | ||
| TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restrict SVG/XML-based uploads and directly renders them when accessed through the domain. By uploading a crafted malicious SVG file containing embedded JavaScript, an attacker will execute arbitrary JavaScript code. This vulnerability directly enables stored XSS exploitation because the payload is persistently stored on your infrastructure (app.typebot.io) and accessible from a public-facing, permanent link. Stored XSS via malicious SVG uploads to app.typebot.io allows attackers to execute arbitrary JavaScript in victims' browsers, enabling session/token theft, account takeover, and exfiltration of sensitive user data. This issue has been fixed in version 3.16.0. | |||||
| CVE-2026-9577 | 2026-07-23 | N/A | 4.8 MEDIUM | ||
| The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL. | |||||
| CVE-2026-9066 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site. | |||||
| CVE-2026-65533 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | |||||
| CVE-2026-65527 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | |||||
| CVE-2026-65519 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | |||||
| CVE-2026-65514 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |||||
| CVE-2026-65510 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |||||
| CVE-2026-65503 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |||||
| CVE-2026-65465 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | |||||
| CVE-2026-65449 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | |||||
| CVE-2026-59517 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |||||
| CVE-2026-57809 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | |||||
| CVE-2026-57428 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | |||||
| CVE-2026-57373 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | |||||
