Export limit exceeded: 403868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 50283 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (50283 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102581 1 Moodle 1 Moodle 2026-10-01 4.6 Medium
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
CVE-2024-58304 1 Spa-cart 2 Spa-cart, Spa-cartcms 2026-10-01 6.1 Medium
SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in administrative users' browsers.
CVE-2022-50896 1 Testa 1 Online Test Management System 2026-10-01 6.1 Medium
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.
CVE-2019-25743 2 Soliloquywp, Wordpress 3 Slider, Soliloquy Lite, Wordpress 2026-10-01 5.4 Medium
WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_title parameter, which are stored and executed when users preview the post.
CVE-2026-64946 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-47096 1 Aja Video Systems 1 Helo Plus 2026-10-01 6.1 Medium
AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.
CVE-2026-103590 1 Webkul 1 Qloapps 2026-10-01 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.
CVE-2026-103249 1 N8n 1 N8n 2026-10-01 7.6 High
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares.
CVE-2026-103343 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14.
CVE-2026-103277 1 Ghost 1 Ghost 2026-10-01 8.1 High
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.
CVE-2026-81160 2 Drupal, Slick Carousel Project 2 Slick Carousel, Slick Carousel 2026-10-01 6.1 Medium
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.
CVE-2026-103292 1 Ghost 1 Ghost 2026-10-01 8 High
Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user's admin session when that user views the affected page.
CVE-2026-93460 1 Basercms Users Community 1 Basercms 2026-10-01 N/A
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2026-93464 1 Basercms Users Community 1 Basercms 2026-10-01 N/A
A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2026-65482 2 La-studioweb, Wordpress 2 Element Kit For Elementor, Wordpress 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3.
CVE-2024-31027 2026-10-01 5.4 Medium
Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.
CVE-2026-100882 1 Krayin 1 Laravel-crm 2026-09-30 2.4 Low
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
CVE-2026-82127 2026-09-30 3.5 Low
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
CVE-2026-85573 2026-09-30 8.8 High
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
CVE-2026-103049 1 Wikimedia 1 Mediawiki-cargo Extension 2026-09-30 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: before 1.46.1.