Total
47168 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-17209 | 1 Ibm | 1 Db2 Mirror For I | 2026-08-21 | N/A | 6.3 MEDIUM |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. | |||||
| CVE-2026-68921 | 2026-08-21 | N/A | 4.7 MEDIUM | ||
| DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight without escaping in packages/@dicebear/initials/src/index.ts. Runtime callers can pass strings despite the numeric TypeScript types, break out of the attributes, and inject arbitrary SVG markup. Script can execute in the page origin when the generated avatar is inserted inline or served as image/svg+xml and opened directly, although exploitation requires an application to pass untrusted values into these normally developer-controlled options. This issue is fixed in @dicebear/core and @dicebear/initials version 9.4.3. | |||||
| CVE-2026-66612 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | |||||
| CVE-2026-50190 | 2026-08-20 | N/A | N/A | ||
| Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into the `pagetitle` template variable and the RainTPL template emits it into the document `<title>` element without HTML escaping. A bookmark title containing `</title><script>...</script>` closes the document title early and the injected script executes in the Shaarli origin for any visitor of `/shaare/{hash}`. Shaarli's metadata fetcher copies a remote page's `<title>` text verbatim into the local bookmark title, so an attacker who hosts an attacker-controlled URL and convinces an administrator to bookmark it plants the payload with no further interaction — and the resulting permalink fires for every visitor including the administrator on first save, providing a one-shot administrator account takeover. Version 0.16.3 fixes the issue. | |||||
| CVE-2025-66824 | 1 Trueconf | 1 Trueconf Server | 2026-08-20 | N/A | 8.7 HIGH |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field. | |||||
| CVE-2025-66823 | 1 Trueconf | 1 Trueconf Server | 2026-08-20 | N/A | 5.4 MEDIUM |
| An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info). | |||||
| CVE-2026-66673 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | |||||
| CVE-2026-66615 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | |||||
| CVE-2026-66605 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |||||
| CVE-2026-66597 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | |||||
| CVE-2026-66590 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | |||||
| CVE-2026-66582 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | |||||
| CVE-2026-73402 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | |||||
| CVE-2026-66616 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | |||||
| CVE-2026-66611 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | |||||
| CVE-2026-66604 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | |||||
| CVE-2026-66601 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | |||||
| CVE-2026-15446 | 2026-08-20 | N/A | 6.4 MEDIUM | ||
| The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time. | |||||
| CVE-2026-15421 | 2026-08-20 | N/A | 6.4 MEDIUM | ||
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. | |||||
| CVE-2026-68564 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | |||||
