Total
47168 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66584 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | |||||
| CVE-2026-28162 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | |||||
| CVE-2026-66623 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |||||
| CVE-2026-66610 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | |||||
| CVE-2026-66599 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | |||||
| CVE-2026-32476 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | |||||
| CVE-2021-24713 | 1 Cminds | 1 Video Lessons Manager | 2026-08-24 | 3.5 LOW | 4.8 MEDIUM |
| The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks | |||||
| CVE-2026-66607 | 2026-08-24 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | |||||
| CVE-2024-31828 | 1 Lavalite | 1 Lavalite | 2026-08-24 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL. | |||||
| CVE-2026-50290 | 2026-08-21 | N/A | N/A | ||
| SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\65xpression(`), null bytes, or CSS comments (`exp/**/ression(`). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for `behavior:`, `-moz-binding`, and `-o-link` patterns. | |||||
| CVE-2026-55850 | 2026-08-21 | N/A | N/A | ||
| Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22. | |||||
| CVE-2026-54681 | 2026-08-21 | N/A | 4.1 MEDIUM | ||
| DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of the markdown setting. Discord's current custom emoji name validation normally excludes attribute-breaking characters, but tampered offline input, a relaxed upstream validation rule, or another future metadata source can inject an HTML attribute and execute script when a user opens the export. This issue is fixed in version 2.47.2. | |||||
| CVE-2026-39878 | 2026-08-21 | N/A | 9.3 CRITICAL | ||
| Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40. | |||||
| CVE-2026-35198 | 2026-08-21 | N/A | 9.0 CRITICAL | ||
| HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue. | |||||
| CVE-2026-76346 | 1 Splunk | 1 Splunk | 2026-08-21 | N/A | 5.4 MEDIUM |
| In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation. | |||||
| CVE-2026-54793 | 1 Dell | 1 Openmanage Enterprise | 2026-08-21 | N/A | 4.6 MEDIUM |
| Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |||||
| CVE-2026-66591 | 2026-08-21 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39. | |||||
| CVE-2026-49825 | 2026-08-21 | N/A | 8.2 HIGH | ||
| lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. | |||||
| CVE-2026-49436 | 2026-08-21 | N/A | 7.3 HIGH | ||
| LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue. | |||||
| CVE-2026-49245 | 2026-08-21 | N/A | 3.7 LOW | ||
| SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3. | |||||
