Vulnerabilities (CVE)

Filtered by CWE-79
Total 47224 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-6864 2026-07-23 N/A 6.1 MEDIUM
The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.
CVE-2026-42506 1 Golang 1 Net 2026-07-23 N/A 6.1 MEDIUM
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-40598 2026-07-23 N/A N/A
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.
CVE-2026-48229 2026-07-23 N/A 5.4 MEDIUM
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into HTML form hidden input value attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.
CVE-2026-9104 2026-07-23 N/A 6.4 MEDIUM
The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The unescaped injection path is triggered specifically when the viewing user lacks edit capabilities, meaning payloads embedded in draft post titles via attribute-breakout techniques execute for unauthenticated users and subscribers.
CVE-2026-39970 2026-07-23 N/A N/A
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restrict SVG/XML-based uploads and directly renders them when accessed through the domain. By uploading a crafted malicious SVG file containing embedded JavaScript, an attacker will execute arbitrary JavaScript code. This vulnerability directly enables stored XSS exploitation because the payload is persistently stored on your infrastructure (app.typebot.io) and accessible from a public-facing, permanent link. Stored XSS via malicious SVG uploads to app.typebot.io allows attackers to execute arbitrary JavaScript in victims' browsers, enabling session/token theft, account takeover, and exfiltration of sensitive user data. This issue has been fixed in version 3.16.0.
CVE-2026-9577 2026-07-23 N/A 4.8 MEDIUM
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
CVE-2026-9066 2026-07-23 N/A 6.1 MEDIUM
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
CVE-2026-65533 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65527 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65519 2026-07-23 N/A 6.5 MEDIUM
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65514 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65510 2026-07-23 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65503 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65465 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
CVE-2026-65449 2026-07-23 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
CVE-2026-59517 2026-07-23 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-57809 2026-07-23 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
CVE-2026-57428 2026-07-23 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
CVE-2026-57373 2026-07-23 N/A 6.5 MEDIUM
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.