Export limit exceeded: 14857 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 48144 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (48144 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-72727 1 Discourse 1 Discourse 2026-08-13 N/A
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVE-2026-73357 2 Nexcess, Wordpress 2 Givewp, Wordpress 2026-08-13 6.5 Medium
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
CVE-2026-21269 1 Adobe 3 Coldfusion, Coldfusion 2023, Coldfusion 2025 2026-08-13 4.6 Medium
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
CVE-2026-66460 2 Aftership & Automizely, Wordpress 2 Aftership Tracking, Wordpress 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
CVE-2026-66449 2 Dylan Kuhn, Wordpress 2 Geo Mashup, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
CVE-2026-73295 1 Squidfunk 1 Mkdocs-material 2026-08-13 5.4 Medium
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
CVE-2026-66655 2 Multiparcels, Wordpress 2 Multiparcels Shipping For Woocommerce, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
CVE-2026-66687 2 Magepeopleteam, Wordpress 2 Wpbookingly, Wordpress 2026-08-13 6.5 Medium
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
CVE-2026-66700 2 Wordpress, Zaytech 2 Wordpress, Smart Online Order For Clover 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
CVE-2026-28175 2 Wordpress, Wp-buy 2 Wordpress, Visitor Traffic Real Time Statistics 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions.
CVE-2026-73572 1 Zimbra 1 Collaboration 2026-08-13 6.1 Medium
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
CVE-2026-61960 2 Themeisle, Wordpress 2 Wp Full Stripe Free, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
CVE-2026-61974 2 Kitae-park, Wordpress 2 Mang Board Wp, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
CVE-2026-73628 1 S9y 1 Serendipity 2026-08-13 6.1 Medium
Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1.
CVE-2026-66468 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
CVE-2026-66467 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-66429 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-65580 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-61965 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-57858 1 Cal.com 1 Cal.com Self-hosted (cal.diy) 2026-08-13 8.9 High
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.