Total
47116 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-83541 | 2026-09-09 | N/A | 6.8 MEDIUM | ||
| The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
| CVE-2026-78742 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | |||||
| CVE-2026-58113 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session. | |||||
| CVE-2025-15690 | 2026-09-09 | N/A | 6.8 MEDIUM | ||
| The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page. The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this. | |||||
| CVE-2026-82089 | 2026-09-09 | N/A | N/A | ||
| The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView. | |||||
| CVE-2026-52370 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL. | |||||
| CVE-2026-78741 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | |||||
| CVE-2026-50980 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record | |||||
| CVE-2026-82090 | 2026-09-09 | N/A | N/A | ||
| Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods. | |||||
| CVE-2026-37710 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function | |||||
| CVE-2025-3271 | 2026-09-09 | N/A | N/A | ||
| Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS | |||||
| CVE-2026-38725 | 2026-09-09 | N/A | 5.4 MEDIUM | ||
| xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site Scripting (XSS). When an administrator reviews comments in the back office, the payload executes with admin-level session context, leading to full store compromise. | |||||
| CVE-2026-50771 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions. | |||||
| CVE-2025-51684 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site. | |||||
| CVE-2022-30983 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | |||||
| CVE-2026-30250 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | |||||
| CVE-2026-77506 | 2026-09-09 | N/A | 4.8 MEDIUM | ||
| Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. | |||||
| CVE-2026-77643 | 2026-09-09 | N/A | 4.4 MEDIUM | ||
| A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. | |||||
| CVE-2026-78325 | 2026-09-09 | N/A | N/A | ||
| Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs. | |||||
| CVE-2026-86550 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites. | |||||
