Total
47249 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-4772 | 2026-07-02 | N/A | 5.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | |||||
| CVE-2026-4770 | 2026-07-02 | N/A | 4.6 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117. | |||||
| CVE-2026-13704 | 2026-07-02 | N/A | 6.4 MEDIUM | ||
| The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Give Worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-13957 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 4.2 MEDIUM |
| Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-27425 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. | |||||
| CVE-2026-57755 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | |||||
| CVE-2026-57678 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16. | |||||
| CVE-2026-57359 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. | |||||
| CVE-2026-57762 | 2026-07-02 | N/A | 5.9 MEDIUM | ||
| Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. | |||||
| CVE-2026-57763 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. | |||||
| CVE-2026-57670 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions. | |||||
| CVE-2026-57345 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. | |||||
| CVE-2026-27402 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. | |||||
| CVE-2025-69152 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | |||||
| CVE-2026-57358 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions. | |||||
| CVE-2026-57426 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions. | |||||
| CVE-2026-57671 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions. | |||||
| CVE-2026-57684 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. | |||||
| CVE-2026-57737 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16. | |||||
| CVE-2026-32208 | 1 Microsoft | 1 Edge Chromium | 2026-07-01 | N/A | 8.8 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | |||||
