Export limit exceeded: 48384 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48384 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-41921 | 1 Koha-community | 1 Koha | 2026-08-18 | 5.4 Medium |
| Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields such as title, author, isbn, publishercode, place, collectiontitle, itemtype, and note, which are stored without sanitization and later rendered in the suggestion list template, causing injected scripts to execute in the browser of any staff user who views the suggestions. | ||||
| CVE-2026-67925 | 1 Jeecgboot | 1 Jeecgboot | 2026-08-18 | 6.1 Medium |
| Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload | ||||
| CVE-2026-30250 | 2026-08-18 | 6.1 Medium | ||
| Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | ||||
| CVE-2026-73382 | 2 Geminilabs, Wordpress | 2 Site Reviews, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | ||||
| CVE-2026-73360 | 2 Premio, Wordpress | 2 Chaty Pro, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | ||||
| CVE-2026-73358 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73190 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-68567 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | ||||
| CVE-2026-66646 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. | ||||
| CVE-2026-66644 | 2 93digital, Wordpress | 2 Typing Effect, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | ||||
| CVE-2026-66640 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||||
| CVE-2026-66638 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66633 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | ||||
| CVE-2026-32547 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | ||||
| CVE-2026-28568 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-16145 | 2 Matthiasnordwig, Wordpress | 2 Invisible Anti-spam & Captcha — Recaptcha Alternative For All Forms, Wordpress | 2026-08-18 | 7.2 High |
| The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The stored payload is written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin's explicit-actions list, which is auto-populated for common form builders at activation and requires no authentication gate to reach the save path. | ||||
| CVE-2026-15604 | 2 Toocheke, Wordpress | 2 Toocheke Companion, Wordpress | 2026-08-18 | 6.4 Medium |
| The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores the raw $_POST value in post meta) and insufficient output escaping in the series admin column rendering (where the stored value is concatenated into a style attribute without esc_attr()). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user, such as an administrator, accesses the series list table in the admin dashboard. | ||||
| CVE-2026-14433 | 2 Vcita, Wordpress | 2 Online Booking & Scheduling Calendar For Wordpress By Vcita, Wordpress | 2026-08-18 | 7.2 High |
| The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-13360 | 2 Wordpress, Wplegalpages | 2 Wordpress, Wplp Cookie Consent – Cookie Banner & Consent Management For Gdpr, Ccpa & Google Consent Mode | 2026-08-18 | 7.2 High |
| The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the site administrator has enabled the 'Support Google Consent Mode (GCM)' setting, which is disabled by default. Additionally, the AJAX handler performs no nonce or capability check, allowing any authenticated user including those with Subscriber-level access to overwrite the affected plugin setting. | ||||
| CVE-2026-11780 | 2 Expresstech, Wordpress | 2 Quiz And Survey Master (qsm) – Easy Quiz And Survey Maker, Wordpress | 2026-08-18 | 6.4 Medium |
| The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||