Vulnerabilities (CVE)

Filtered by CWE-79
Total 47181 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-73184 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
CVE-2026-73360 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
CVE-2026-73358 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
CVE-2026-73393 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
CVE-2026-27365 2026-08-20 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0.
CVE-2026-73359 2026-08-20 N/A 6.5 MEDIUM
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73342 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-32333 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
CVE-2026-66596 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
CVE-2026-66633 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
CVE-2026-66637 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
CVE-2026-66640 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
CVE-2026-32547 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
CVE-2026-73190 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
CVE-2026-28568 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-73361 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
CVE-2026-19904 2026-08-20 3.3 LOW 2.4 LOW
A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used.
CVE-2026-66638 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-15066 2026-08-20 N/A 6.4 MEDIUM
The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-75091 2026-08-20 N/A 7.2 HIGH
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.