Vulnerabilities (CVE)

Filtered by CWE-79
Total 45528 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-14203 2026-07-27 N/A 4.8 MEDIUM
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
CVE-2026-14856 2026-07-27 N/A N/A
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.
CVE-2026-15928 2026-07-27 N/A N/A
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
CVE-2026-55730 2026-07-27 N/A N/A
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.
CVE-2026-12496 2026-07-27 N/A N/A
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
CVE-2026-65764 2026-07-27 N/A N/A
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-15425 2026-07-27 N/A 6.4 MEDIUM
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL.
CVE-2026-66434 2026-07-27 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
CVE-2026-59558 2026-07-27 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59239 2026-07-27 N/A N/A
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
CVE-2026-65597 1 N8n 1 N8n 2026-07-27 N/A 5.4 MEDIUM
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue.
CVE-2026-65592 1 N8n 1 N8n 2026-07-27 N/A 5.4 MEDIUM
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.
CVE-2026-66475 2026-07-27 N/A 5.9 MEDIUM
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.
CVE-2026-66445 2026-07-27 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
CVE-2026-65563 2026-07-27 N/A 5.9 MEDIUM
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
CVE-2026-65562 2026-07-27 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
CVE-2026-66448 2026-07-27 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
CVE-2026-59556 2026-07-27 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-65561 2026-07-27 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
CVE-2026-59553 2026-07-27 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.