Export limit exceeded: 48671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48671 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-74902 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-08-21 | 8.6 High |
| SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor. | ||||
| CVE-2026-73336 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||||
| CVE-2026-74252 | 1 J2commerce.com | 1 J2store Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name. | ||||
| CVE-2026-27365 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-08-21 | 5.9 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | ||||
| CVE-2026-18371 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | ||||
| CVE-2026-18372 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. | ||||
| CVE-2026-71960 | 1 Shenzhen Cudy Technology | 1 Wr3000 2.0 | 2026-08-21 | 9.1 Critical |
| Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface. | ||||
| CVE-2026-66581 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||
| CVE-2026-77028 | 1 Yootheme.com | 1 Zoo Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | ||||
| CVE-2026-76612 | 1 Yootheme.com | 1 Zoo Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector. | ||||
| CVE-2026-75933 | 1 Jet Admin | 1 Jet Admin | 2026-08-21 | 7.3 High |
| Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain. | ||||
| CVE-2026-55850 | 1 Element-hq | 1 Element-web | 2026-08-21 | N/A |
| Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22. | ||||
| CVE-2026-54681 | 1 Tyrrrz | 1 Discordchatexporter | 2026-08-21 | 4.1 Medium |
| DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of the markdown setting. Discord's current custom emoji name validation normally excludes attribute-breaking characters, but tampered offline input, a relaxed upstream validation rule, or another future metadata source can inject an HTML attribute and execute script when a user opens the export. This issue is fixed in version 2.47.2. | ||||
| CVE-2026-66603 | 2 Dartiss, Wordpress | 2 Draft List, Wordpress | 2026-08-21 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4. | ||||
| CVE-2026-14287 | 2 10web, Wordpress | 2 10web Booster, Wordpress | 2026-08-21 | 4.7 Medium |
| The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page. | ||||
| CVE-2026-14334 | 2 Wordpress, Wpdevart | 2 Wordpress, Booking Calendar, Appointment Booking System | 2026-08-21 | 8.8 High |
| The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking. | ||||
| CVE-2026-19615 | 2 Bowo, Wordpress | 2 Admin And Site Enhancements Ase, Wordpress | 2026-08-21 | 6.8 Medium |
| The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it. | ||||
| CVE-2026-76565 | 1 Phoca | 1 Phoca Cart Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | ||||
| CVE-2026-76569 | 1 Phoca | 1 Phoca Download Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | ||||
| CVE-2026-76564 | 1 Phoca | 1 Phoca Cart Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 | ||||