Export limit exceeded: 48707 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48707 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81167 | 2026-09-02 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25. | ||||
| CVE-2026-81201 | 2026-09-02 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3. | ||||
| CVE-2026-81160 | 2026-09-02 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | ||||
| CVE-2026-81288 | 2 Wordpress, Wp Swings | 2 Wordpress, Upsell Order Bump Offer For Woocommerce | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | ||||
| CVE-2026-81775 | 2 Estatik, Wordpress | 2 Estatik, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | ||||
| CVE-2026-83562 | 2026-09-02 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | ||||
| CVE-2026-81771 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | ||||
| CVE-2026-81770 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | ||||
| CVE-2026-81289 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | ||||
| CVE-2026-84781 | 2026-09-02 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | ||||
| CVE-2026-84438 | 1 Opencart | 1 Opencart | 2026-09-02 | 3.5 Low |
| A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument firstname causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81807 | 2026-09-02 | 8.8 High | ||
| The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | ||||
| CVE-2026-81737 | 2026-09-02 | 8.8 High | ||
| The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator. | ||||
| CVE-2026-79621 | 2026-09-02 | 4.3 Medium | ||
| The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry. | ||||
| CVE-2026-77792 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-02 | 7.5 High |
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | ||||
| CVE-2026-19723 | 2026-09-02 | 7.1 High | ||
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-19719 | 2026-09-02 | 6.8 Medium | ||
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-12865 | 2026-09-02 | 7.1 High | ||
| The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScript in the victim's authenticated session via an auto-firing onfocus handler. The Galleries/Albums sink renders only when the site has more than 20 galleries/albums (the normal state of a populated install). | ||||
| CVE-2025-15664 | 2026-09-02 | 6.8 Medium | ||
| The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider. | ||||
| CVE-2025-15663 | 2026-09-02 | 6.8 Medium | ||
| The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider. | ||||