Search Results (48762 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-85302 2026-09-03 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.
CVE-2026-81295 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
CVE-2026-81773 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
CVE-2026-84848 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
CVE-2026-84812 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-81776 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
CVE-2026-81282 2026-09-03 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
CVE-2026-81281 2026-09-03 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
CVE-2026-84232 1 Redhat 5 Ansible Automation Platform, Rhui, Satellite and 2 more 2026-09-03 5.4 Medium
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.
CVE-2024-7952 2 Rockwell Automation, Rockwellautomation 2 Dataedgeplatform Datamosaix Private Cloud, Dataedgeplatform Datamosaix Private Cloud 2026-09-03 N/A
A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.
CVE-2025-15692 2 Icegram, Wordpress 2 Icegram Express, Wordpress 2026-09-03 3.5 Low
The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-84665 1 Jenkins Project 1 Jenkins Sonarqube Scanner Plugin 2026-09-03 8 High
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2026-84673 1 Jenkins Project 1 Jenkins Customizable Header Plugin 2026-09-03 8.8 High
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.
CVE-2026-85021 1 Langgenius 1 Dify 2026-09-03 4.3 Medium
A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-84437 1 Opencart 1 Opencart 2026-09-03 3.5 Low
A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argument address_1 results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-19719 2 Inisev, Wordpress 2 Social Media Share Buttons & Social Sharing Icons, Wordpress 2026-09-03 6.8 Medium
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
CVE-2026-19723 2 Inisev, Wordpress 2 Social Media Share Buttons & Social Sharing Icons, Wordpress 2026-09-03 7.1 High
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
CVE-2026-82884 2 Aioseo, Wordpress 2 All In One Seo, Wordpress 2026-09-03 6.8 Medium
The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post.
CVE-2026-3457 2 Thales, Thalesgroup 2 Sentinel Ldk Runtime, Sentinel Ldk Runtime 2026-09-03 6.8 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22.
CVE-2026-84677 1 Jenkins Project 1 Jenkins Update-center2 2026-09-03 5.4 Medium
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.