| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component. |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session. |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session. |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link. |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link. |
| AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session. |
| The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability. |
| The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them. |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS.
This issue affects Mediawiki - Cargo extension: before 1.46.1. |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS.
This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10. |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS.
This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10. |
| Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`. |
| The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5. |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS.
This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS.
This issue affects Mediawiki - WikiSEO Extension: from * before 1.46.1, 1.45.5, 1.43.10. |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS.
This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. |
| Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality. |
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. |