Total
45470 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-44227 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. There are no effective workarounds. Avoid following untrusted RT URLs. This issue has been fixed in version 6.0.3. | |||||
| CVE-2026-47687 | 2026-07-23 | N/A | 7.3 HIGH | ||
| FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user input. An unauthenticated attacker who knows any registered host's MAC address can POST a malicious `sysproduct` value to `/service/inventory.php`, which is stored in the database. When an administrator opens Reports > Inventory, the payload breaks out of the `<option>` element and executes arbitrary JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue. | |||||
| CVE-2026-47689 | 2026-07-23 | N/A | 4.6 MEDIUM | ||
| FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates using `str_replace()` without any HTML escaping. An unauthenticated attacker who knows any registered host's MAC address can POST malicious inventory values (e.g. `sysproduct`, `sysserial`) to `/service/inventory.php`, which stores them in the database. When an administrator opens the Group Inventory tab, the payload renders as executable HTML/JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue. | |||||
| CVE-2026-47685 | 2026-07-23 | N/A | 7.3 HIGH | ||
| FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without sanitization, and the Host Management Inventory page renders all static inventory fields into HTML without output encoding, allowing stored cross-site scripting that executes in any administrator's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue. | |||||
| CVE-2026-2445 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag. | |||||
| CVE-2026-64828 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions. | |||||
| CVE-2026-9577 | 2026-07-23 | N/A | 4.8 MEDIUM | ||
| The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL. | |||||
| CVE-2026-9066 | 2026-07-23 | N/A | 6.1 MEDIUM | ||
| The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site. | |||||
| CVE-2026-65533 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | |||||
| CVE-2026-65527 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | |||||
| CVE-2026-65519 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | |||||
| CVE-2026-65514 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |||||
| CVE-2026-65510 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |||||
| CVE-2026-65503 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |||||
| CVE-2026-65465 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | |||||
| CVE-2026-65449 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | |||||
| CVE-2026-59517 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |||||
| CVE-2026-57809 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | |||||
| CVE-2026-57428 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | |||||
| CVE-2026-57373 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | |||||
