Total
47156 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81814 | 2026-08-28 | N/A | N/A | ||
| Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user views the calendar. The fix changes: titleEl.innerHTML = arg.event.title to: titleEl.textContent = arg.event.title || '' and similarly stops using innerHTML for the static download icon. Version impacted =>3.3.0 | |||||
| CVE-2026-11747 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |||||
| CVE-2026-81820 | 2026-08-28 | N/A | N/A | ||
| Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object name; * attribute value; * attribute type; * comment; * first/last seen values; * IDS flag. Those values were concatenated directly into HTML strings before rendering. The upstream commit explicitly states that DOMPurify removed XSS vectors but still allowed other HTML elements, such as forms, through. The fix replaces direct string interpolation with DOM construction via document.createElement() and assigns all attacker-controlled values using textContent. The headline is similarly converted to escaped HTML through a temporary element. Version impacted =>3.3.0 | |||||
| CVE-2026-5738 | 2026-08-28 | N/A | 6.1 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-81753 | 2026-08-28 | N/A | N/A | ||
| Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permission to create or edit a note could store a crafted Mermaid payload that results in JavaScript execution when another user views the affected case note. The patch adds explicit Mermaid detection and HTML escaping around the token content before the generated Mermaid wrapper is returned. It also moves the wrapping logic earlier in page initialization so Markdown instances are protected consistently. Version impacted >= 3.3.0 | |||||
| CVE-2026-18478 | 2026-08-28 | N/A | N/A | ||
| Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10 | |||||
| CVE-2026-46594 | 2026-08-28 | N/A | N/A | ||
| A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1. | |||||
| CVE-2026-64972 | 2026-08-28 | N/A | N/A | ||
| ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but that does not prevent XSS in the parent frameset rendered by preview.php itself. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. | |||||
| CVE-2026-64970 | 2026-08-28 | N/A | N/A | ||
| ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile template echoes the phone value without output encoding and the browser executes the payload leading to the theft of user's session cookie. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. | |||||
| CVE-2026-40126 | 2026-08-28 | N/A | N/A | ||
| OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2 | |||||
| CVE-2026-64971 | 2026-08-28 | N/A | N/A | ||
| ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. | |||||
| CVE-2026-78273 | 2026-08-28 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions. | |||||
| CVE-2026-78281 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |||||
| CVE-2026-78261 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | |||||
| CVE-2026-78283 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |||||
| CVE-2026-78293 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | |||||
| CVE-2026-78289 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | |||||
| CVE-2026-73572 | 1 Synacor | 1 Zimbra Collaboration Suite | 2026-08-28 | N/A | 6.1 MEDIUM |
| In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information. | |||||
| CVE-2026-71386 | 1 Adobe | 1 Coldfusion | 2026-08-28 | N/A | 8.8 HIGH |
| is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | |||||
| CVE-2026-48414 | 2026-08-28 | N/A | 7.7 HIGH | ||
| Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed. | |||||
