Export limit exceeded: 14857 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 48144 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48144 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72727 | 1 Discourse | 1 Discourse | 2026-08-13 | N/A |
| Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. | ||||
| CVE-2026-73357 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-13 | 6.5 Medium |
| Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-21269 | 1 Adobe | 3 Coldfusion, Coldfusion 2023, Coldfusion 2025 | 2026-08-13 | 4.6 Medium |
| is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | ||||
| CVE-2026-66460 | 2 Aftership & Automizely, Wordpress | 2 Aftership Tracking, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | ||||
| CVE-2026-66449 | 2 Dylan Kuhn, Wordpress | 2 Geo Mashup, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | ||||
| CVE-2026-73295 | 1 Squidfunk | 1 Mkdocs-material | 2026-08-13 | 5.4 Medium |
| Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7. | ||||
| CVE-2026-66655 | 2 Multiparcels, Wordpress | 2 Multiparcels Shipping For Woocommerce, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | ||||
| CVE-2026-66687 | 2 Magepeopleteam, Wordpress | 2 Wpbookingly, Wordpress | 2026-08-13 | 6.5 Medium |
| Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. | ||||
| CVE-2026-66700 | 2 Wordpress, Zaytech | 2 Wordpress, Smart Online Order For Clover | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | ||||
| CVE-2026-28175 | 2 Wordpress, Wp-buy | 2 Wordpress, Visitor Traffic Real Time Statistics | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | ||||
| CVE-2026-73572 | 1 Zimbra | 1 Collaboration | 2026-08-13 | 6.1 Medium |
| In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information. | ||||
| CVE-2026-61960 | 2 Themeisle, Wordpress | 2 Wp Full Stripe Free, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | ||||
| CVE-2026-61974 | 2 Kitae-park, Wordpress | 2 Mang Board Wp, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | ||||
| CVE-2026-73628 | 1 S9y | 1 Serendipity | 2026-08-13 | 6.1 Medium |
| Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1. | ||||
| CVE-2026-66468 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | ||||
| CVE-2026-66467 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66429 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-65580 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | ||||
| CVE-2026-61965 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | ||||
| CVE-2026-57858 | 1 Cal.com | 1 Cal.com Self-hosted (cal.diy) | 2026-08-13 | 8.9 High |
| Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events. | ||||