CWE-79
Cross-site Scripting (XSS)
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 50 of 293- CVE-2026-9629Medium· 6.432 m ago
The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenti
- CVE-2026-3297Medium· 6.432 m ago
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output esc
- CVE-2026-9134Medium· 6.41 h ago
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in
- CVE-2026-9109High· 7.21 h ago
The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due
- CVE-2026-53608High· 8.710 h ago
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogle
- CVE-2026-54395—11 h ago
MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HT
- CVE-2026-54393—11 h ago
A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation
- CVE-2026-53606Medium· 5.411 h ago
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 's
- CVE-2026-45014—11 h ago
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name in draft version tooltip. As of time of publication, no k
- CVE-2026-45011High· 7.3EPSS 0%11 h ago
Apostrophe has stored XSS via javascript: URL in Image Widget Link
npm - CVE-2026-44990Critical· 9.3EPSS 0%11 h ago
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
npm - CVE-2026-12130Low· 3.511 h ago
A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle resu
- CVE-2026-12129Low· 3.511 h ago
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument tod
- CVE-2026-41003High· 7.6EPSS 0%12 h ago
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 thr
- CVE-2026-46342—EPSS 0%13 h ago
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
npm - CVE-2026-46609Medium· 4.6EPSS 0%13 h ago
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patch
- CVE-2026-53724—EPSS 0%13 h ago
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a
- CVE-2026-42897High· 8.1KEVEPSS 8%16 h ago
Microsoft Exchange Server Cross-Site Scripting Vulnerability
- CVE-2025-68461High· 7.2KEVEPSS 7%16 h ago
RoundCube Webmail Cross-site Scripting Vulnerability
- CVE-2020-11023Medium· 6.9KEVEXPLOITEPSS 34%16 h ago
JQuery Cross-Site Scripting (XSS) Vulnerability
npmrubygemsnugetmavenpackagist - CVE-2024-37383Medium· 6.1KEVEXPLOITEPSS 64%16 h ago
RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
- CVE-2023-37580Medium· 6.1KEVEPSS 94%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2020-35730Medium· 6.1KEVEPSS 67%16 h ago
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
- CVE-2018-19943High· 8.0KEVEPSS 7%16 h ago
QNAP NAS File Station Cross-Site Scripting Vulnerability
- CVE-2024-44309Medium· 6.3KEVEPSS 1%16 h ago
Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
- CVE-2020-3580Medium· 6.1KEVEPSS 93%16 h ago
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
- CVE-2013-5223Medium· 5.4KEVEXPLOITEPSS 30%16 h ago
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
- CVE-2022-24682Medium· 6.1KEVEPSS 89%16 h ago
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
- CVE-2024-43573Medium· 6.5KEVEPSS 18%16 h ago
Microsoft Windows MSHTML Platform Spoofing Vulnerability
- CVE-2021-1879Medium· 6.1KEVEPSS 1%16 h ago
Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
- CVE-2019-9978Medium· 6.1KEVEXPLOITEPSS 88%16 h ago
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-11182Medium· 6.1KEVEPSS 14%16 h ago
MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-42009Critical· 9.3KEVEPSS 91%16 h ago
RoundCube Webmail Cross-Site Scripting Vulnerability
- CVE-2019-18426High· 8.2KEVEXPLOITEPSS 61%16 h ago
WhatsApp Cross-Site Scripting Vulnerability
- CVE-2012-0767Medium· 6.1KEVEPSS 15%16 h ago
Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-27443Medium· 6.1KEVEPSS 33%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2018-6882Medium· 6.1KEVEPSS 77%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2025-27915Medium· 5.4KEVEPSS 26%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
- CVE-2023-34192Critical· 9.0KEVEPSS 90%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2025-66376High· 7.2KEVEPSS 11%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
- CVE-2022-27926Medium· 6.1KEVEPSS 94%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2022-39197Medium· 6.1KEVEPSS 20%16 h ago
Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
- CVE-2022-42948Critical· 9.8KEVEPSS 22%16 h ago
Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
- CVE-2023-43770Medium· 6.1KEVEPSS 81%16 h ago
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
- CVE-2021-26829Medium· 5.4KEVEPSS 8%16 h ago
OpenPLC ScadaBR Cross-site Scripting Vulnerability
- CVE-2019-3929Critical· 9.8KEVEXPLOITEPSS 94%16 h ago
Crestron Multiple Products Command Injection Vulnerability
- CVE-2014-2120Medium· 6.1KEVEPSS 75%16 h ago
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
- CVE-2023-5631Medium· 6.1KEVEPSS 83%16 h ago
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
- CVE-2018-19953Medium· 6.1KEVEPSS 32%16 h ago
QNAP NAS File Station Cross-Site Scripting Vulnerability
- CVE-2025-48700Medium· 6.1KEVEPSS 18%16 h ago
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.