Total
45310 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-57620 | 2026-06-26 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | |||||
| CVE-2026-57617 | 2026-06-26 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. | |||||
| CVE-2026-57322 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. | |||||
| CVE-2026-56043 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | |||||
| CVE-2025-33128 | 1 Ibm | 1 Engineering Workflow Management | 2026-06-26 | N/A | 5.4 MEDIUM |
| IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2026-54013 | 1 Openwebui | 1 Open Webui | 2026-06-26 | N/A | 7.6 HIGH |
| Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. The ModelMeta class has no validate_profile_image_url field validator, and the model image serving endpoint has no MIME allowlist or nosniff header. Any authenticated user with workspace.models permission (enabled by default) can store a data:image/svg+xml;base64,... payload in a model's profile image and achieve full account takeover of anyone who navigates to the image URL. This vulnerability is fixed in 0.9.6. | |||||
| CVE-2026-7569 | 1 Quest | 1 Netvault Backup | 2026-06-26 | N/A | 8.8 HIGH |
| Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the viewclient webpage. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28202. | |||||
| CVE-2026-44311 | 1 Fabricjs | 1 Fabric.js | 2026-06-26 | N/A | 5.4 MEDIUM |
| Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG serialization via the toSVG() method. Specifically, the color field within the colorStops array of a fabric.Gradient object is not properly escaped when converted into SVG <stop> elements. If an application renders the generated SVG string into the DOM, this may allow an attacker to inject arbitrary HTML/SVG and execute JavaScript in the victim's browser. This vulnerability is fixed in 7.4.0. | |||||
| CVE-2026-6658 | 2026-06-26 | N/A | 5.4 MEDIUM | ||
| A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export. | |||||
| CVE-2026-56761 | 1 Hono | 1 Hono | 2026-06-26 | N/A | 4.3 MEDIUM |
| hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements. | |||||
| CVE-2026-54070 | 2026-06-26 | N/A | 7.1 HIGH | ||
| SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute sanitizer is an event-handler blocklist: allowAttr rejects only attribute names present in a fixed eventAttrs map copied from the w3schools legacy handler list. That map omits modern event handlers. onpointerover, onpointerdown, onauxclick, onbeforetoggle, onfocusin, onanimationstart, and ontransitionend are not in the list, so the sanitizer passes them through verbatim on any tag. The frontend assigns the rendered HTML to mdElement.innerHTML in app/src/config/bazaar.ts with no client-side DOMPurify on this path, into a normal element in the main document (no iframe, no sandbox). The kernel sends no Content-Security-Policy, X-Frame-Options, or X-Content-Type-Options header on any response, so an inline handler runs when its event fires. The README is rendered when an Administrator opens a package in Settings → Marketplace, after the one-time marketplace trust consent. Install is not required. Result: a third-party Bazaar package author runs JavaScript in the Administrator's authenticated SiYuan origin when the Administrator views and interacts with the package listing, and gains full control of the workspace. This vulnerability is fixed in 3.7.0. | |||||
| CVE-2026-10086 | 1 Gitlab | 1 Gitlab | 2026-06-26 | N/A | 8.7 HIGH |
| GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input. | |||||
| CVE-2026-10712 | 1 Gitlab | 1 Gitlab | 2026-06-26 | N/A | 8.0 HIGH |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions. | |||||
| CVE-2026-57651 | 2026-06-26 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions. | |||||
| CVE-2026-57638 | 2026-06-26 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions. | |||||
| CVE-2026-57618 | 2026-06-26 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. | |||||
| CVE-2026-57317 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | |||||
| CVE-2026-56072 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. | |||||
| CVE-2026-56045 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | |||||
| CVE-2026-56044 | 2026-06-26 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | |||||
