Search Results (44806 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73359 2 Wordpress, Wp Legal Pages 2 Wordpress, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent 2026-08-21 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73375 2 Supsystic, Wordpress 2 Ultimate Maps By Supsystic, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2025-9211 1 Otalio 1 Ship Property Management System 2026-08-21 6.7 Medium
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
CVE-2026-52854 1 Professionalwiki 1 Maps 2026-08-21 8.6 High
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3.
CVE-2026-15421 2 Siteground, Wordpress 2 Speed Optimizer – The All-in-one Performance-boosting Plugin, Wordpress 2026-08-21 6.4 Medium
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings.
CVE-2026-66358 1 Extra Innovation 2 Acmailer Cgi, Acmailer Db 2026-08-21 N/A
A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.
CVE-2026-15446 2 Nosilver4u, Wordpress 2 Ewww Image Optimizer, Wordpress 2026-08-21 6.4 Medium
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.
CVE-2026-73182 2 Jeff Starr, Wordpress 2 Bbq Pro, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
CVE-2026-68921 1 Dicebear 1 Dicebear 2026-08-21 4.7 Medium
DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight without escaping in packages/@dicebear/initials/src/index.ts. Runtime callers can pass strings despite the numeric TypeScript types, break out of the attributes, and inject arbitrary SVG markup. Script can execute in the page origin when the generated avatar is inserted inline or served as image/svg+xml and opened directly, although exploitation requires an application to pass untrusted values into these normally developer-controlled options. This issue is fixed in @dicebear/core and @dicebear/initials version 9.4.3.
CVE-2026-73354 2 Reichertbrothers, Wordpress 2 Simplyrets Real Estate Idx, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
CVE-2026-66590 2 Tagembed, Wordpress 2 Tagembed, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
CVE-2026-66598 2 Kingtech Llc., Wordpress 2 B2bking Premium, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
CVE-2026-66605 2 Hasthemes, Wordpress 2 Swatchly – Woocommerce Variation Swatches For Products, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
CVE-2026-66606 2 Themegrill, Wordpress 2 Smartsmtp, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
CVE-2026-66673 2 Monkeysan, Wordpress 2 Flatastic, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
CVE-2026-68564 2 Notificationx, Wordpress 2 Notificationx Pro, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
CVE-2026-40508 1 Openemr 1 Openemr 2026-08-21 5.4 Medium
OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can inject malicious scripts through the template upload functionality, which are stored without sanitization and execute in the browser of any other Forms Administration user who views the template in the HTML editor.
CVE-2026-75948 1 Icagenda.com 1 Icagenda Extension For Joomla 2026-08-21 N/A
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
CVE-2026-65644 1 Rocket.chat 1 Rocket.chat 2026-08-21 N/A
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
CVE-2026-21580 1 Atlassian 2 Confluence Data Center, Confluence Server 2026-08-21 N/A
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.