Vulnerabilities (CVE)

Filtered by CWE-79
Total 47263 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21855 1 Tarkov 1 Tarkov Data Manager 2026-06-17 N/A 9.3 CRITICAL
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scripting (XSS) vulnerability in the toast notification system allows any attacker to execute arbitrary JavaScript in the context of a victim's browser session by crafting a malicious URL. A series of fix commits on 02 January 2025 fixed this and other vulnerabilities.
CVE-2026-21788 1 Hcltech 1 Connections 2026-06-17 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
CVE-2026-21730 1 Verint 1 Verba Collaboration Compliance And Quality Management Platform 2026-06-17 N/A 6.1 MEDIUM
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization, an attacker can inject a malicious XSS payload into the username field. This payload will be executed in the context of the administrator’s browser when the admin accesses the web application's log viewer. The vendor was notified early about this vulnerability, but didn't respond to our messages. This issue was fixed in version 10.0.6
CVE-2026-21664 1 Aquaplatform 1 Revive Adserver 2026-06-17 N/A 6.1 MEDIUM
HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and malicious scripts would be executed.
CVE-2026-21663 1 Aquaplatform 1 Revive Adserver 2026-06-17 N/A 6.1 MEDIUM
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and malicious scripts would be executed.
CVE-2026-21642 1 Aquaplatform 1 Revive Adserver 2026-06-17 N/A 6.1 MEDIUM
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and malicious scripts would be executed.
CVE-2026-21632 1 Joomla 1 Joomla\! 2026-06-17 N/A 5.4 MEDIUM
Lack of output escaping for article titles leads to XSS vectors in various locations.
CVE-2026-21631 1 Joomla 1 Joomla\! 2026-06-17 N/A 5.4 MEDIUM
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-21624 1 Stackideas 1 Easydiscuss 2026-06-17 N/A 5.4 MEDIUM
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
CVE-2026-21623 1 Stackideas 1 Easydiscuss 2026-06-17 N/A 5.4 MEDIUM
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
CVE-2026-21529 1 Microsoft 1 Azure Hdinsight 2026-06-17 N/A 5.7 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
CVE-2026-21483 1 Nadh 1 Listmonk 2026-06-17 N/A 5.4 MEDIUM
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious JavaScript into campaigns or templates. When a higher-privileged user (Super Admin) views or previews this content, the XSS executes in their browser context, allowing the attacker to perform privileged actions such as creating backdoor admin accounts. The attack can be weaponized via the public archive feature, where victims simply need to visit a link - no preview click required. Version 6.0.0 fixes the issue.
CVE-2026-21451 1 Webkul 1 Bagisto 2026-06-17 N/A 8.4 HIGH
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HTTP POST request before submission. As a result, arbitrary JavaScript can be stored in the CMS content and executed whenever the page is viewed or edited. This exposes administrators to a high-severity risk, including complete account takeover, backend hijacking, and malicious script execution. Version 2.3.10 fixes the issue.
CVE-2026-21432 1 Emlog 1 Emlog 2026-06-17 N/A 5.4 MEDIUM
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are available.
CVE-2026-21431 1 Emlog 1 Emlog 2026-06-17 N/A 5.4 MEDIUM
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `Resource media library ` function while publishing an article. As of time of publication, no known patched versions are available.
CVE-2026-21430 1 Emlog 1 Emlog 2026-06-17 N/A 9.3 CRITICAL
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
CVE-2026-21393 2026-06-17 N/A 5.4 MEDIUM
Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
CVE-2026-21264 1 Microsoft 1 Account 2026-06-17 N/A 9.3 CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20959 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-20945 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.