Export limit exceeded: 48197 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48197 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14290 | 2026-08-14 | 6.8 Medium | ||
| The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post. | ||||
| CVE-2026-72832 | 1 Getgrav | 1 Grav | 2026-08-14 | 5.4 Medium |
| Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which cannot cross the first literal `>`; when a `>` appears inside a quoted attribute value the browser keeps the tag open and parses a subsequent event handler (e.g. onerror), so the detector and browser disagree. A page editor without admin.super privileges can save page content such as `<img src=x title=">" onerror=alert(document.domain)>`, which is accepted, stored, and executed in the site origin when any visitor (including unauthenticated users) views the page. Fixed in 2.0.13. | ||||
| CVE-2026-53472 | 1 Kubev2v | 1 Migration-planner | 2026-08-14 | 6.3 Medium |
| A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information. | ||||
| CVE-2026-19871 | 1 Roskus | 1 Prospero Flow Crm | 2026-08-14 | N/A |
| Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field. | ||||
| CVE-2026-18084 | 1 Blackberry | 2 Uem, Unified Endpoint Manager | 2026-08-14 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | ||||
| CVE-2026-70355 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2019, Sharepoint Server Subscription Edition | 2026-08-14 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-64900 | 1 Microsoft | 4 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 and 1 more | 2026-08-14 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-27537 | 2 Supsysticcom, Wordpress | 2 Smart Popup By Supsystic, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||||
| CVE-2026-28004 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||||
| CVE-2026-61965 | 2 Ahmad, Wordpress | 2 Geekybot, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | ||||
| CVE-2026-66429 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66456 | 2 Bestwebsoft, Wordpress | 2 Profile Extra Fields, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | ||||
| CVE-2026-66467 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcommunity | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-73340 | 2 Fifu, Wordpress | 2 Featured Image From Url, Wordpress | 2026-08-14 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | ||||
| CVE-2026-72821 | 1 Getgrav | 1 Grav | 2026-08-14 | 5.4 Medium |
| Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form. | ||||
| CVE-2026-19794 | 2 Gamerz, Wordpress | 2 Wp-stats, Wordpress | 2026-08-14 | 7.2 High |
| The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-18109 | 2 Boldgrid, Wordpress | 2 W3 Total Cache, Wordpress | 2026-08-14 | 7.2 High |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. | ||||
| CVE-2026-65480 | 2 Codexthemes, Wordpress | 2 Thegem, Wordpress | 2026-08-14 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. | ||||
| CVE-2026-73648 | 1 Rubyonrails | 1 Rails Html Sanitizers | 2026-08-14 | 5.4 Medium |
| rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1. | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||