Search Results (48822 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66616 2 10web, Wordpress 2 Form Maker By 10web, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
CVE-2026-50190 1 Shaarli 1 Shaarli 2026-08-20 N/A
Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into the `pagetitle` template variable and the RainTPL template emits it into the document `<title>` element without HTML escaping. A bookmark title containing `</title><script>...</script>` closes the document title early and the injected script executes in the Shaarli origin for any visitor of `/shaare/{hash}`. Shaarli's metadata fetcher copies a remote page's `<title>` text verbatim into the local bookmark title, so an attacker who hosts an attacker-controlled URL and convinces an administrator to bookmark it plants the payload with no further interaction — and the resulting permalink fires for every visitor including the administrator on first save, providing a one-shot administrator account takeover. Version 0.16.3 fixes the issue.
CVE-2026-64972 1 Atutor 1 Atutor 2026-08-20 N/A
ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but that does not prevent XSS in the parent frameset rendered by preview.php itself. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVE-2026-75526 1 Django-cms 1 Django Cms 2026-08-20 4.4 Medium
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values to ContentRenderer.render_exception when plugin rendering fails in edit mode. Values from get_short_description(), the exception message, the placeholder, or placeholder.source are interpolated into a cms-rendering-exception heading and later returned through mark_safe. Because the heading is not escaped, stored HTML executes in an editor’s browser, and settings.DEBUG does not prevent the custom heading from rendering. The fix uses format_html to escape the message before safe placeholder output is returned. This issue is fixed in versions 5.0.9.
CVE-2026-73259 1 Cesanta 1 Mongoose 2026-08-20 5.4 Medium
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22.
CVE-2026-61986 2 Wasiliy Strecker, Wordpress 2 Contest Gallery, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
CVE-2025-66824 1 Trueconf 2 Server, Trueconf Server 2026-08-20 7.3 High
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
CVE-2025-66823 1 Trueconf 2 Server, Trueconf Server 2026-08-20 3.5 Low
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
CVE-2026-66615 2 Eric Teubert, Wordpress 2 Podlove Podcast Publisher, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
CVE-2026-66597 2 Melograno Venture Studio, Wordpress 2 Wpdatatables, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
CVE-2026-66582 2 Cozmoslabs, Wordpress 2 Translatepress, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-66604 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
CVE-2026-66601 2 Davidlingren, Wordpress 2 Media Library Assistant, Wordpress 2026-08-20 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-73402 2 Hakan Ozevin, Wordpress 2 Wp Base Booking, Wordpress 2026-08-20 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
CVE-2026-64970 1 Atutor 1 Atutor 2026-08-20 N/A
ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile template echoes the phone value without output encoding and the browser executes the payload leading to the theft of user's session cookie. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVE-2026-64971 1 Atutor 1 Atutor 2026-08-20 N/A
ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVE-2026-66612 2 Thembay, Wordpress 2 Aora, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
CVE-2026-71386 1 Adobe 3 Coldfusion, Coldfusion 2023, Coldfusion 2025 2026-08-20 8.8 High
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVE-2026-19929 1 Openboxes 1 Openboxes 2026-08-20 6.3 Medium
A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 will fix this issue. The identifier of the patch is deeac6a4a7aba86ce99c4bda37142e41d209293e. It is recommended to upgrade the affected component.
CVE-2026-74992 2 Kirki, Wordpress 2 Kirki, Wordpress 2026-08-20 6.8 Medium
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.