Export limit exceeded: 403868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 50283 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50283 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102581 | 1 Moodle | 1 Moodle | 2026-10-01 | 4.6 Medium |
| A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post. | ||||
| CVE-2024-58304 | 1 Spa-cart | 2 Spa-cart, Spa-cartcms | 2026-10-01 | 6.1 Medium |
| SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers. | ||||
| CVE-2022-50896 | 1 Testa | 1 Online Test Management System | 2026-10-01 | 6.1 Medium |
| Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context. | ||||
| CVE-2019-25743 | 2 Soliloquywp, Wordpress | 3 Slider, Soliloquy Lite, Wordpress | 2026-10-01 | 5.4 Medium |
| WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_title parameter, which are stored and executed when users preview the post. | ||||
| CVE-2026-64946 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | ||||
| CVE-2026-47096 | 1 Aja Video Systems | 1 Helo Plus | 2026-10-01 | 6.1 Medium |
| AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session. | ||||
| CVE-2026-103590 | 1 Webkul | 1 Qloapps | 2026-10-01 | 5.4 Medium |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session. | ||||
| CVE-2026-103249 | 1 N8n | 1 N8n | 2026-10-01 | 7.6 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares. | ||||
| CVE-2026-103343 | 2026-10-01 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. | ||||
| CVE-2026-103277 | 1 Ghost | 1 Ghost | 2026-10-01 | 8.1 High |
| Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access. | ||||
| CVE-2026-81160 | 2 Drupal, Slick Carousel Project | 2 Slick Carousel, Slick Carousel | 2026-10-01 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | ||||
| CVE-2026-103292 | 1 Ghost | 1 Ghost | 2026-10-01 | 8 High |
| Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user's admin session when that user views the affected page. | ||||
| CVE-2026-93460 | 1 Basercms Users Community | 1 Basercms | 2026-10-01 | N/A |
| A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | ||||
| CVE-2026-93464 | 1 Basercms Users Community | 1 Basercms | 2026-10-01 | N/A |
| A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | ||||
| CVE-2026-65482 | 2 La-studioweb, Wordpress | 2 Element Kit For Elementor, Wordpress | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3. | ||||
| CVE-2024-31027 | 2026-10-01 | 5.4 Medium | ||
| Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality. | ||||
| CVE-2026-100882 | 1 Krayin | 1 Laravel-crm | 2026-09-30 | 2.4 Low |
| A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component. | ||||
| CVE-2026-82127 | 2026-09-30 | 3.5 Low | ||
| The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability. | ||||
| CVE-2026-85573 | 2026-09-30 | 8.8 High | ||
| The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them. | ||||
| CVE-2026-103049 | 1 Wikimedia | 1 Mediawiki-cargo Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: before 1.46.1. | ||||