Total
47209 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65882 | 2026-07-28 | N/A | 6.1 MEDIUM | ||
| Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector. | |||||
| CVE-2026-64810 | 1 Jetbrains | 1 Intellij Idea | 2026-07-28 | N/A | 4.3 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | |||||
| CVE-2026-51565 | 2026-07-28 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request | |||||
| CVE-2026-65448 | 2026-07-28 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | |||||
| CVE-2026-65446 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | |||||
| CVE-2026-65441 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | |||||
| CVE-2026-65439 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | |||||
| CVE-2026-59727 | 2026-07-28 | N/A | N/A | ||
| Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4. | |||||
| CVE-2026-65437 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |||||
| CVE-2026-65438 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | |||||
| CVE-2026-65443 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | |||||
| CVE-2026-65440 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |||||
| CVE-2026-61957 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | |||||
| CVE-2026-65447 | 2026-07-28 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | |||||
| CVE-2026-44387 | 2026-07-28 | N/A | 5.2 MEDIUM | ||
| ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |||||
| CVE-2026-59729 | 2026-07-28 | N/A | N/A | ||
| Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "' >/= or whitespace are dropped. A second attribute-rendering path, renderHTMLElement() in packages/astro/src/runtime/server/render/dom.ts, has its own inline attribute loop that does not go through addAttribute() and was not updated. It interpolates the attribute name unescaped and only escapes the value, so untrusted prop keys spread onto a native-HTMLElement-subclass component can still break out of the attribute context. This issue has been fixed in version 7.0.6. | |||||
| CVE-2026-8167 | 2026-07-28 | N/A | 6.1 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026. | |||||
| CVE-2026-15016 | 2026-07-28 | N/A | 6.4 MEDIUM | ||
| The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-15393 | 2026-07-28 | N/A | 6.4 MEDIUM | ||
| The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-66029 | 2026-07-28 | N/A | 5.4 MEDIUM | ||
| Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Manage Clients or Manage Client Projects pages where client names are rendered unsanitized. | |||||
