Export limit exceeded: 49702 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49702 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-7171 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-28 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-7172 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-28 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-7170 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-28 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-18147 | 1 Redhat | 2 Enterprise Linux, Freeipa | 2026-09-28 | 8.1 High |
| A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted. | ||||
| CVE-2026-15917 | 1 Drupal | 1 Drupal Core | 2026-09-28 | 4.7 Medium |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. | ||||
| CVE-2026-81655 | 1 Wordpress-extensions | 1 Ad Inserter | 2026-09-28 | 7.5 High |
| The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors. | ||||
| CVE-2026-85002 | 1 Wordpress-extensions | 1 Embedpress | 2026-09-28 | 6.8 Medium |
| The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post. | ||||
| CVE-2026-86609 | 1 Wordpress-extensions | 1 Download Manager Pro | 2026-09-28 | 8.8 High |
| The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature. | ||||
| CVE-2026-89006 | 1 Wordpress-extensions | 1 Wpematico Rss Feed Fetcher | 2026-09-28 | 6.8 Medium |
| The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2026-96895 | 1 Wordpress-extensions | 1 Wp Youtube Lyte | 2026-09-28 | 6.8 Medium |
| The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2026-96899 | 1 Wordpress-extensions | 1 Optima Express Idx | 2026-09-28 | 6.8 Medium |
| The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2026-97319 | 1 Wordpress-extensions | 1 Powerpress | 2026-09-28 | 6.8 Medium |
| The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2026-100882 | 1 Krayin | 1 Laravel-crm | 2026-09-27 | 2.4 Low |
| A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component. | ||||
| CVE-2026-100673 | 1 Getgrav | 1 Grav | 2026-09-27 | 8.2 High |
| The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5. | ||||
| CVE-2025-15696 | 1 Wordpress-extensions | 1 Real3d Flipbook Lite | 2026-09-27 | 6.8 Medium |
| The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators. | ||||
| CVE-2026-95528 | 2 Magazine3, Wordpress-extensions | 2 Core Web Vitals & Pagespeed Booster, Core Web Vitals& Pagespeed Booster | 2026-09-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | ||||
| CVE-2026-95530 | 2 Pixelyoursite, Wordpress-extensions | 2 Pixelyoursite – Your Smart Pixel (tag) Manager, Pixelyoursite | 2026-09-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. | ||||
| CVE-2026-84151 | 1 Wordpress-extensions | 1 The Post Grid | 2026-09-27 | 3.5 Low |
| The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content. | ||||
| CVE-2026-89002 | 1 Wordpress-extensions | 1 Wpematico Rss Feed Fetcher | 2026-09-27 | 6.8 Medium |
| The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign. | ||||
| CVE-2026-89005 | 1 Wordpress-extensions | 1 Wpematico Rss Feed Fetcher | 2026-09-27 | 6.8 Medium |
| The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign. | ||||