Vulnerabilities (CVE)

Filtered by CWE-79
Total 47116 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-83541 2026-09-09 N/A 6.8 MEDIUM
The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-78742 2026-09-09 N/A 6.1 MEDIUM
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.
CVE-2026-58113 2026-09-09 N/A 6.1 MEDIUM
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
CVE-2025-15690 2026-09-09 N/A 6.8 MEDIUM
The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page. The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this.
CVE-2026-82089 2026-09-09 N/A N/A
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.
CVE-2026-52370 2026-09-09 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
CVE-2026-78741 2026-09-09 N/A 6.1 MEDIUM
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
CVE-2026-50980 2026-09-09 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record
CVE-2026-82090 2026-09-09 N/A N/A
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.
CVE-2026-37710 2026-09-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function
CVE-2025-3271 2026-09-09 N/A N/A
Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
CVE-2026-38725 2026-09-09 N/A 5.4 MEDIUM
xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site Scripting (XSS). When an administrator reviews comments in the back office, the payload executes with admin-level session context, leading to full store compromise.
CVE-2026-50771 2026-09-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.
CVE-2025-51684 2026-09-09 N/A 6.1 MEDIUM
CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site.
CVE-2022-30983 2026-09-09 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
CVE-2026-30250 2026-09-09 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code
CVE-2026-77506 2026-09-09 N/A 4.8 MEDIUM
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.
CVE-2026-77643 2026-09-09 N/A 4.4 MEDIUM
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
CVE-2026-78325 2026-09-09 N/A N/A
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
CVE-2026-86550 2026-09-09 N/A 6.5 MEDIUM
NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.