Total
45310 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-57686 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions. | |||||
| CVE-2026-57672 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions. | |||||
| CVE-2026-57360 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | |||||
| CVE-2026-57354 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions. | |||||
| CVE-2026-57349 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. | |||||
| CVE-2026-57342 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions. | |||||
| CVE-2026-27430 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions. | |||||
| CVE-2026-27426 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions. | |||||
| CVE-2026-27408 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions. | |||||
| CVE-2026-27404 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions. | |||||
| CVE-2026-10089 | 2026-07-02 | N/A | 6.4 MEDIUM | ||
| The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while the custom field VALUE is sanitized with wp_kses_post(), the custom field KEY ($key) is interpolated into the rendered HTML (lines 1786-1791) and echoed (line 1806) without any escaping when an inserted page is rendered with the [insert page='ID' display='all'] shortcode. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2025-69154 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. | |||||
| CVE-2025-69153 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. | |||||
| CVE-2026-4770 | 2026-07-02 | N/A | 4.6 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117. | |||||
| CVE-2026-4772 | 2026-07-02 | N/A | 5.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | |||||
| CVE-2026-58263 | 2026-07-02 | N/A | 7.2 HIGH | ||
| Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value, potentially causing Mutation XSS. When an application supplies attacker-influenced HTML to the editor's value-set or insertion paths, the sanitized output still contains a live <img ... onload=...> (or another non-onerror handler such as onfocus). A consumer that renders that output (element.innerHTML = editor.value) executes the handler with no user interaction. This issue has been fixed in version 4.12.28. | |||||
| CVE-2026-13704 | 2026-07-02 | N/A | 6.4 MEDIUM | ||
| The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Give Worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-13957 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 4.2 MEDIUM |
| Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-57426 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions. | |||||
| CVE-2026-57345 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. | |||||
