Export limit exceeded: 49886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49886 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103686 | 1 Rhukster | 1 Dom-sanitizer | 2026-10-01 | 3.5 Low |
| A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component. | ||||
| CVE-2026-81160 | 2 Drupal, Slick Carousel Project | 2 Slick Carousel, Slick Carousel | 2026-10-01 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | ||||
| CVE-2026-103292 | 1 Ghost | 1 Ghost | 2026-10-01 | 8 High |
| Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user's admin session when that user views the affected page. | ||||
| CVE-2026-102394 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | ||||
| CVE-2026-103339 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0. | ||||
| CVE-2026-103063 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | ||||
| CVE-2026-103064 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | ||||
| CVE-2026-103343 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. | ||||
| CVE-2026-92412 | 2026-10-01 | 7.1 High | ||
| The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator. | ||||
| CVE-2026-87973 | 2026-10-01 | 3.1 Low | ||
| The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page. | ||||
| CVE-2026-87970 | 2026-10-01 | 4.7 Medium | ||
| The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link. | ||||
| CVE-2026-86610 | 2026-10-01 | 6.4 Medium | ||
| The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there. | ||||
| CVE-2026-81739 | 2026-10-01 | 7.5 High | ||
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator. | ||||
| CVE-2026-103489 | 2026-10-01 | 2 Low | ||
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | ||||
| CVE-2026-103493 | 2026-10-01 | 8.1 High | ||
| In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | ||||
| CVE-2026-103277 | 1 Ghost | 1 Ghost | 2026-10-01 | 8.1 High |
| Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access. | ||||
| CVE-2026-103249 | 1 N8n | 1 N8n | 2026-10-01 | 7.6 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares. | ||||
| CVE-2026-64946 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | ||||
| CVE-2026-64950 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards. | ||||
| CVE-2026-7176 | 1 Crocantickets | 1 Entradium | 2026-10-01 | N/A |
| CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event. | ||||