Total
47224 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65470 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | |||||
| CVE-2026-61944 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | |||||
| CVE-2026-59513 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | |||||
| CVE-2026-59512 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | |||||
| CVE-2026-57769 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | |||||
| CVE-2026-57767 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | |||||
| CVE-2026-57701 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | |||||
| CVE-2026-57397 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | |||||
| CVE-2026-35016 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers can craft a malicious request containing a JavaScript payload in the frm_query parameter that executes in the victim's browser when submitted. | |||||
| CVE-2026-35007 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. Attackers can craft a malicious URL containing a JavaScript payload in the id parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-35008 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a malicious URL containing a JavaScript payload in the id parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-30691 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode | |||||
| CVE-2026-35010 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-4293 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser. | |||||
| CVE-2026-7613 | 2026-07-23 | N/A | 7.2 HIGH | ||
| The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-35009 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-5783 | 2026-07-23 | N/A | 7.6 HIGH | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: before V24.29750.1.0. | |||||
| CVE-2026-35013 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Attackers can craft a malicious URL containing a JavaScript payload in either parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-35012 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. | |||||
| CVE-2026-47099 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted JSON payload containing a malicious _constructor-name_ property value. The custom reviver passes the constructor name directly to new Function() without sanitization when recreating object prototypes, enabling attackers to inject arbitrary JavaScript through vectors such as postMessage in cross-frame communication contexts to achieve script execution within the application. | |||||
