Export limit exceeded: 48704 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48704 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83562 | 2026-09-02 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | ||||
| CVE-2026-81775 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | ||||
| CVE-2026-81771 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | ||||
| CVE-2026-81770 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | ||||
| CVE-2026-81289 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | ||||
| CVE-2026-81288 | 2026-09-02 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | ||||
| CVE-2026-84781 | 2026-09-02 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | ||||
| CVE-2026-84438 | 1 Opencart | 1 Opencart | 2026-09-02 | 3.5 Low |
| A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument firstname causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81807 | 2026-09-02 | 8.8 High | ||
| The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | ||||
| CVE-2026-81737 | 2026-09-02 | 8.8 High | ||
| The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator. | ||||
| CVE-2026-79621 | 2026-09-02 | 4.3 Medium | ||
| The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry. | ||||
| CVE-2026-77792 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-02 | 7.5 High |
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | ||||
| CVE-2026-19723 | 2026-09-02 | 7.1 High | ||
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-19719 | 2026-09-02 | 6.8 Medium | ||
| The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | ||||
| CVE-2026-12865 | 2026-09-02 | 7.1 High | ||
| The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScript in the victim's authenticated session via an auto-firing onfocus handler. The Galleries/Albums sink renders only when the site has more than 20 galleries/albums (the normal state of a populated install). | ||||
| CVE-2025-15664 | 2026-09-02 | 6.8 Medium | ||
| The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider. | ||||
| CVE-2025-15663 | 2026-09-02 | 6.8 Medium | ||
| The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider. | ||||
| CVE-2026-84803 | 1 B3log | 1 Siyuan | 2026-09-02 | 9 Critical |
| SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces. | ||||
| CVE-2026-84793 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 4.8 Medium |
| Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages. | ||||
| CVE-2026-75528 | 2 Wordpress, Wpmudev | 2 Wordpress, Broken Link Checker | 2026-09-02 | 7.2 High |
| The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to perform the plugin's standard dismiss-and-recheck workflow on a link submitted by the attacker via the WordPress comment author URL field, after which the attacker's HTTP server issues a redirect to a URL containing an HTML/JavaScript payload that is stored verbatim in the link log. | ||||