Export limit exceeded: 49702 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (49702 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96873 | 1 Wikimedia | 1 Mediawiki-cirrussearch Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0. | ||||
| CVE-2026-100237 | 1 Wikimedia | 1 Mediawiki-thanks Extension | 2026-09-27 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * before 1.43.10/1.45.5/1.46.1. | ||||
| CVE-2026-100376 | 1 Wikimedia | 1 Mediawiki - Templatesandbox Extension | 2026-09-27 | N/A |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-85081 | 1 Wordpress-extensions | 3 File Manager, File Manager Pro, Fileorganizer | 2026-09-27 | 7.5 High |
| The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it. | ||||
| CVE-2026-96874 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | ||||
| CVE-2026-96875 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | ||||
| CVE-2026-96876 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | ||||
| CVE-2026-96877 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | ||||
| CVE-2026-96878 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-27 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | ||||
| CVE-2026-100380 | 1 Wikimedia | 1 Mediawiki-wikibase Extension | 2026-09-27 | N/A |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2025-47828 | 2026-09-27 | 6.4 Medium | ||
| Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings. | ||||
| CVE-2026-88618 | 1 1024-lab | 1 Smartadmin | 2026-09-27 | 6.5 Medium |
| 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code. | ||||
| CVE-2026-96531 | 1 Wordpress-extensions | 1 Optimole | 2026-09-26 | 6.8 Medium |
| The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post. | ||||
| CVE-2026-92411 | 1 Wordpress-extensions | 1 Wp Delicious | 2026-09-26 | 6.8 Medium |
| The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed. | ||||
| CVE-2026-84096 | 1 Wordpress-extensions | 1 Wp Review Slider Pro | 2026-09-26 | 8.0 High |
| The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-84095 | 1 Wordpress-extensions | 1 Wp Review Slider Pro | 2026-09-26 | 8.0 High |
| The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-75684 | 3 Adobe, Apple, Microsoft | 6 Adobe Connect, Adobe Connect Android Mobile App, Connect and 3 more | 2026-09-26 | 9.3 Critical |
| Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | ||||
| CVE-2026-16591 | 1 Wordpress-extensions | 1 Wp Directory Kit | 2026-09-26 | 7.2 High |
| The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page. | ||||
| CVE-2026-15273 | 2 Automatic.css, Wordpress-extensions | 2 Automatic.css, Automatic.css | 2026-09-26 | 6.4 Medium |
| The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses the Activity Log settings page. | ||||
| CVE-2026-100720 | 1 Froxlor | 1 Froxlor | 2026-09-26 | 8.7 High |
| Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits scalar cells through Twig's `raw` filter, disabling HTML auto-escaping, so when an administrator or reseller opens Domains > SSL certificates the attacker-supplied issuer value executes as script in the privileged user's session. This crosses a privilege boundary from customer to admin and can result in full administrator account takeover; because a Froxlor admin controls webserver, DNS, and PHP configuration applied by a cron job running as root, the issue can be further escalated to command execution as root on the managed server. The issue is fixed in Froxlor 2.3.12. | ||||