| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post. |
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page. |
| MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.
A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.
Impact:
- Arbitrary script execution in the context of the victim's MISP session
- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim
- Affects both the default and Overmind UI themes
Affected versions: <2.5.48 |
| MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.
When another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim's browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.
Preconditions:
- Attacker must hold galaxy editor privileges (local or via sync).
- Victim must view the affected cluster and click the malicious link.
Impact:
- Stored cross-site scripting (XSS) in the victim's browser.
- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.
Affected: <2.5.48. |
| Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions. |
| Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. |
| Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. |
| Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions. |
| Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions. |
| Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS.
This issue affects LayerSlider: from n/a through 8.4.0. |
| Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. |
| Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. |