Export limit exceeded: 50186 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50186 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104450 | 1 Yeswiki | 1 Yeswiki | 2026-10-02 | 6.5 Medium |
| YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, title, and description fields to any page rendering {{pointimage}} to append raw HTML or JavaScript to any wiki page, including pages whose write ACL restricts editing, causing stored cross-site scripting in viewers' and administrators' browsers. | ||||
| CVE-2026-101890 | 2 Codexonics, Wordpress-extensions | 2 Prime Mover, Prime Mover | 2026-10-02 | 5.4 Medium |
| The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory so that the malicious value renders unescaped in the column_site_title() method of PrimeMoverBackupMenuListTable.php, triggering script execution in an administrator's browser when they view the Prime Mover Packages list table without needing to restore the package. | ||||
| CVE-2026-102666 | 1 Joyland | 1 Joyland.ai | 2026-10-02 | 6.5 Medium |
| The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once. | ||||
| CVE-2026-55395 | 1 Teledyne Flir | 1 Aware2 | 2026-10-02 | N/A |
| Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation. | ||||
| CVE-2026-13718 | 1 Wordpress-extensions | 1 Tabs Responsive | 2026-10-02 | 6.8 Medium |
| The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | ||||
| CVE-2026-85016 | 1 Wordpress-extensions | 1 Unlimited Elements For Elementor | 2026-10-02 | 6.8 Medium |
| The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | ||||
| CVE-2026-91022 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 6.8 Medium |
| The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. | ||||
| CVE-2026-71542 | 1 Getsimple-ce | 1 Getsimple Cms | 2026-10-02 | N/A |
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-93875 | 2026-10-02 | 7.2 High | ||
| The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel. | ||||
| CVE-2026-104466 | 1 Yeswiki | 1 Yeswiki | 2026-10-02 | 5.4 Medium |
| YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror handler, executing JavaScript in viewers' browsers, including administrators. | ||||
| CVE-2026-85613 | 1 Openpanel | 1 Openpanel | 2026-10-02 | 8.2 High |
| OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints. | ||||
| CVE-2026-102831 | 1 Jupyter | 3 Jupyter Core, Jupyterlab, Notebook | 2026-10-02 | 8.1 High |
| JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4. | ||||
| CVE-2026-102264 | 1 Mwasikz | 1 Robo-cafe-rms | 2026-10-02 | 3.5 Low |
| A vulnerability was found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element is an unknown function of the file frontend/update-account.php of the component Edit Profile Feature. Performing a manipulation of the argument Name/Address/City results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-56005 | 2 Melapress, Wordpress | 2 Wp Activity Log, Wordpress | 2026-10-02 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows Stored XSS.This issue affects WP Activity Log: from n/a through 5.6.3.1. | ||||
| CVE-2026-73382 | 2 Geminilabs, Wordpress | 2 Site Reviews, Wordpress | 2026-10-02 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0. | ||||
| CVE-2026-93463 | 1 Basercms Users Community | 1 Basercms | 2026-10-02 | N/A |
| A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | ||||
| CVE-2026-70560 | 1 Ultimatefosters | 1 Ultimatepos | 2026-10-01 | 5.4 Medium |
| Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin. | ||||
| CVE-2023-53983 | 1 Ateme | 7 Flamingo, Flamingo Xl, Flamingo Xl Firmware and 4 more | 2026-10-01 | 9.8 Critical |
| Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | ||||
| CVE-2026-55230 | 1 Givanz | 1 Vvveb | 2026-10-01 | 8.7 High |
| Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6. | ||||
| CVE-2026-97260 | 2 Maxfoundry, Wordpress-extensions | 2 Maxgalleria, Maxgalleria | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||