Total
45528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-14203 | 2026-07-27 | N/A | 4.8 MEDIUM | ||
| The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | |||||
| CVE-2026-14856 | 2026-07-27 | N/A | N/A | ||
| A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account. | |||||
| CVE-2026-15928 | 2026-07-27 | N/A | N/A | ||
| XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. | |||||
| CVE-2026-55730 | 2026-07-27 | N/A | N/A | ||
| Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter. | |||||
| CVE-2026-12496 | 2026-07-27 | N/A | N/A | ||
| Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request. | |||||
| CVE-2026-65764 | 2026-07-27 | N/A | N/A | ||
| Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |||||
| CVE-2026-15425 | 2026-07-27 | N/A | 6.4 MEDIUM | ||
| The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL. | |||||
| CVE-2026-66434 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | |||||
| CVE-2026-59558 | 2026-07-27 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | |||||
| CVE-2026-59239 | 2026-07-27 | N/A | N/A | ||
| Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message. | |||||
| CVE-2026-65597 | 1 N8n | 1 N8n | 2026-07-27 | N/A | 5.4 MEDIUM |
| n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue. | |||||
| CVE-2026-65592 | 1 N8n | 1 N8n | 2026-07-27 | N/A | 5.4 MEDIUM |
| n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser. | |||||
| CVE-2026-66475 | 2026-07-27 | N/A | 5.9 MEDIUM | ||
| Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | |||||
| CVE-2026-66445 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | |||||
| CVE-2026-65563 | 2026-07-27 | N/A | 5.9 MEDIUM | ||
| Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | |||||
| CVE-2026-65562 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | |||||
| CVE-2026-66448 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | |||||
| CVE-2026-59556 | 2026-07-27 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | |||||
| CVE-2026-65561 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |||||
| CVE-2026-59553 | 2026-07-27 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | |||||
