Export limit exceeded: 50171 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50171 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105060 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4. | ||||
| CVE-2026-104396 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from n/a through 1.34.2. | ||||
| CVE-2026-102914 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | ||||
| CVE-2026-102393 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7. | ||||
| CVE-2026-105173 | 1 Code-projects | 1 Human Resource Management | 2026-10-05 | 3.5 Low |
| A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. | ||||
| CVE-2026-103344 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-05 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-104400 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. | ||||
| CVE-2026-105086 | 1 Wwbn | 1 Avideo | 2026-10-05 | 8.7 High |
| WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages. | ||||
| CVE-2026-94171 | 2 Villatheme, Wordpress-extensions | 2 Curcy, Curcy | 2026-10-05 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY woo-multi-currency allows DOM-Based XSS.This issue affects CURCY: 2.2.18. | ||||
| CVE-2026-73546 | 1 Envoyproxy | 1 Envoy | 2026-10-05 | 7.4 High |
| Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. | ||||
| CVE-2026-105289 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 3.5 Low |
| A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105069 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5. | ||||
| CVE-2026-103084 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. | ||||
| CVE-2026-104404 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0. | ||||
| CVE-2026-5782 | 1 Loglama.net | 1 Turkhotspot | 2026-10-05 | 5.2 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in MRV Technology Foreign Trade Ltd. Co. TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-103489 | 1 Jetbrains | 1 Youtrack | 2026-10-05 | 2 Low |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | ||||
| CVE-2026-59788 | 1 Zabbix | 1 Zabbix | 2026-10-05 | 4.8 Medium |
| The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent. | ||||
| CVE-2026-17005 | 1 Wordpress-extensions | 1 Horizontal Scrolling Announcements | 2026-10-05 | 6.8 Medium |
| The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement. | ||||
| CVE-2026-105291 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 4.3 Medium |
| A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-104119 | 1 Wordpress-extensions | 1 Simple Shopping Cart | 2026-10-05 | 3.5 Low |
| The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability. | ||||