Export limit exceeded: 48589 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48589 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75626 | 1 Smicallef | 1 Spiderfoot | 2026-08-21 | 9.3 Critical |
| SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys. | ||||
| CVE-2026-19447 | 1 Fileorbis | 1 Fileorbis | 2026-08-21 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOrbis: before 16.5. | ||||
| CVE-2026-66633 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms Pro Add On Pack | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | ||||
| CVE-2026-66639 | 2 Wordpress, Wpzoom | 2 Wordpress, Wpzoom Forms – Contact Form Plugin For Gutenberg | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | ||||
| CVE-2026-66640 | 2 Marcus (aka @msykes), Wordpress | 2 Login With Ajax, Wordpress | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||||
| CVE-2026-66643 | 2 Wordpress, Wronganswersonly | 2 Wordpress, Wufoo Shortcode | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | ||||
| CVE-2026-66645 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Table Of Contents Block | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | ||||
| CVE-2026-66646 | 2 Mythemeshop, Wordpress | 2 Wp Tab Widget, Wordpress | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. | ||||
| CVE-2026-68567 | 2 Wordpress, Wp Grids | 2 Wordpress, Convert Pro | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | ||||
| CVE-2026-73338 | 2 Autopay, Wordpress | 2 Autopay, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | ||||
| CVE-2026-73342 | 2 Magazine3, Wordpress | 2 Wp Multilang, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. | ||||
| CVE-2026-73359 | 2 Wordpress, Wp Legal Pages | 2 Wordpress, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent | 2026-08-21 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | ||||
| CVE-2026-73375 | 2 Supsystic, Wordpress | 2 Ultimate Maps By Supsystic, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2025-9211 | 1 Otalio | 1 Ship Property Management System | 2026-08-21 | 6.7 Medium |
| Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting | ||||
| CVE-2026-52854 | 1 Professionalwiki | 1 Maps | 2026-08-21 | 8.6 High |
| Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3. | ||||
| CVE-2026-15421 | 2 Siteground, Wordpress | 2 Speed Optimizer – The All-in-one Performance-boosting Plugin, Wordpress | 2026-08-21 | 6.4 Medium |
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. | ||||
| CVE-2026-66358 | 1 Extra Innovation | 2 Acmailer Cgi, Acmailer Db | 2026-08-21 | N/A |
| A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | ||||
| CVE-2026-15446 | 2 Nosilver4u, Wordpress | 2 Ewww Image Optimizer, Wordpress | 2026-08-21 | 6.4 Medium |
| The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time. | ||||
| CVE-2026-73182 | 2 Jeff Starr, Wordpress | 2 Bbq Pro, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | ||||
| CVE-2026-68921 | 1 Dicebear | 1 Dicebear | 2026-08-21 | 4.7 Medium |
| DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight without escaping in packages/@dicebear/initials/src/index.ts. Runtime callers can pass strings despite the numeric TypeScript types, break out of the attributes, and inject arbitrary SVG markup. Script can execute in the page origin when the generated avatar is inserted inline or served as image/svg+xml and opened directly, although exploitation requires an application to pass untrusted values into these normally developer-controlled options. This issue is fixed in @dicebear/core and @dicebear/initials version 9.4.3. | ||||