On this page
Atomicorp WAF Rule 333141
Rule Summary
- Rule ID: 333141
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Potential XSS Attack detected
- Observed CWEs: CWE-20 (5), CWE-22 (3), CWE-73 (1), CWE-74 (2), CWE-78 (2), CWE-79 (586), CWE-80 (5), CWE-81 (1), CWE-83 (3), CWE-87 (1), CWE-89 (4), CWE-94 (94), CWE-116 (7), CWE-183 (1), CWE-200 (3), CWE-264 (1), CWE-287 (1), CWE-295 (2), CWE-306 (2), CWE-345 (3), CWE-352 (4), CWE-384 (1), CWE-434 (6), CWE-444 (1), CWE-601 (2), CWE-610 (1), CWE-611 (2), CWE-639 (2), CWE-665 (1), CWE-693 (1), CWE-732 (1), CWE-798 (1), CWE-862 (1), CWE-915 (1), CWE-918 (1), CWE-1321 (1)
- Revision: 22
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request headers, Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Potential XSS Attack detected” in the request headers, request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 (v3.0) | Critical |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 (v3.0) | Critical |
| CVE-2018-6220 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6223 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6228 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6229 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2023-1719 | Bitrix Component - Cross-Site Scripting | bitrix24 | 9.8 (v3.1) | Critical |
| CVE-2026-67688 | ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution Vulnerability | ICS-Park Smart Park Management System v2.0 | 9.8 (v3.1) | Critical |
| CVE-2023-1892 | Sidekiq < 7.0.8 - Cross-Site Scripting | sidekiq | 9.6 (v3.1) | Critical |
| CVE-2026-54694 | NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover | skills-service | 9.6 (v3.1) | Critical |
| CVE-2026-55085 | Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite | etherpad | 9.6 (v3.1) | Critical |
| CVE-2026-73043 | SiYuan before v3.7.4 Remote Code Execution via Template Calculation | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73044 | SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73050 | SiYuan before v3.7.4 Stored XSS via select option color | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73052 | SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73053 | SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji | siyuan | 9.4 (v4.0) | Critical |
| CVE-2024-58355 | Cal.com through 4.7.15 Cross-Site Scripting via booking questions | cal.diy | 9.3 (v4.0) | Critical |
| CVE-2026-42849 | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover | authentik | 9.3 (v3.1) | Critical |
| CVE-2026-45118 | MyBB: Contact page reflected XSS | mybb | 9.3 (v3.1) | Critical |
| CVE-2026-57858 | Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID | Cal.com Self-Hosted (Cal.diy) | 9.3 (v4.0) | Critical |
| CVE-2026-66394 | SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-66396 | SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-66418 | OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field | openclaw agent dashboard | 9.3 (v4.0) | Critical |
| CVE-2026-74902 | SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-78997 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) Cross-Site Scripting Vulnerability | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) | 9.3 (v3.1) | Critical |
| CVE-2026-88866 | WWBN AVideo LoginControl Stored XSS via User-Agent Header | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-88867 | WWBN AVideo Stored XSS via Category Name and Icon Class | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-88868 | AVideo LiveLinks Stored XSS via title and description fields | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-88869 | AVideo AD_Server Stored XSS via log.php label parameter | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-89249 | AVideo YPTWallet Stored XSS via CryptoWallet Configuration | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-89253 | AVideo Stored XSS via donationLink in watch page button | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-89254 | AVideo CustomizeUser Stored XSS via field_name Parameter | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-89255 | AVideo LoginControl Stored XSS via PGP Public Key | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-89256 | AVideo Bookmark Plugin Stored XSS via Chapter Names | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-84189 | LibreNMS before 26.7.0 Stored XSS via Oxidized API | librenms | 9.2 (v4.0) | Critical |
| CVE-2026-89243 | WWBN AVideo Stored XSS via UserGroups setGroup_name | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-34448 | SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop cl | siyuan | 9.0 (v3.1) | Critical |
| CVE-2026-35198 | HeyForm vulnerable to stored XSS via form field titles | heyform | 9.0 (v3.1) | Critical |
| CVE-2026-42556 | Postiz stored XSS in public preview page | postiz | 9.0 (v3.1) | Critical |
| CVE-2026-43984 | Tautulli has stored XSS in logFile via guest-controlled log_js_errors input | Tautulli | 8.9 (v3.1) | High |
| CVE-2016-8526 | Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting | airwave | 8.8 (v3.0) | High |
| CVE-2018-1213 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 8.8 (v3.0) | High |
| CVE-2018-6224 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.8 (v3.0) | High |
| CVE-2021-20086 | Odoo Apps - Cross-Site Scripting via Prototype Pollution | jquery-bbq | 8.8 (v3.1) | High |
| CVE-2025-56798 | Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery Vulnerability | Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier | 8.8 (v3.1) | High |
| CVE-2026-12968 | Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload | Product Addons and Product Options With Custom Fields | 8.8 (v3.1) | High |
| CVE-2026-41473 | CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints | cyberpanel | 8.8 (v4.0) | High |
| CVE-2026-42455 | LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin) | linkwarden | 8.8 (v4.0) | High |
| CVE-2026-8071 | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass | Anti-Spam by CleanTalk. Spam protection | 8.8 (v3.1) | High |
| CVE-2026-12496 | Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server | LIP-ME20xC | 8.7 (v4.0) | High |
| CVE-2026-15217 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | gitlab | 8.7 (v3.1) | High |
| CVE-2026-44667 | Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering | faction | 8.7 (v3.1) | High |
| CVE-2026-44669 | Faction: Stored XSS in Assessment Attachment Filename Preview Rendering | faction | 8.7 (v3.1) | High |
| CVE-2026-44729 | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers) | twenty | 8.7 (v3.1) | High |
| CVE-2026-45115 | MyBB: Buddy/ignore list username XSS | mybb | 8.7 (v3.1) | High |
| CVE-2026-45116 | MyBB: Profile field type confusion XSS | mybb | 8.7 (v3.1) | High |
| CVE-2026-45270 | CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule | ci4ms | 8.7 (v3.1) | High |
| CVE-2026-46518 | OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics | openemr | 8.7 (v3.1) | High |
| CVE-2026-47665 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML | penpot | 8.7 (v3.1) | High |
| CVE-2026-47743 | Shopper: Multiple data integrity and disclosure issues in admin Livewire components | shopper | 8.7 (v3.1) | High |
| CVE-2026-48026 | lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML | lakeFS | 8.7 (v3.1) | High |
| CVE-2026-48527 | HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint | haxcms-nodejs | 8.7 (v3.1) | High |
| CVE-2026-53758 | Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized | emlog | 8.7 (v4.0) | High |
| CVE-2026-54347 | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover | froxlor | 8.7 (v3.1) | High |
| CVE-2026-68899 | Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback | wekan | 8.7 (v3.1) | High |
| CVE-2026-70492 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages | open-webui | 8.7 (v3.1) | High |
| CVE-2024-23167 | GestSup - Cross-Site Scripting | gestsup | 8.6 | High |
| CVE-2025-66024 | XWiki Blog Application home page vulnerable to Stored XSS via Post Title | blog application | 8.6 (v4.0) | High |
| CVE-2026-34463 | MantisBT has Stored HTML Injection/XSS via Clone Issue Form | mantisbt | 8.6 (v4.0) | High |
| CVE-2026-49864 | wetty vulnerable to DOM XSS via file-download filename | wetty | 8.6 (v4.0) | High |
| CVE-2026-59239 | Stored XSS in Prospero Flow CRM email body allows administrator account takeover | Prospero Flow CRM | 8.6 (v4.0) | High |
| CVE-2026-67328 | @better-auth/sso before 1.6.21 Account Takeover via SSO | sso | 8.6 (v4.0) | High |
| CVE-2026-84803 | SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist | siyuan | 8.6 (v4.0) | High |
| CVE-2026-21618 | Cross-site scripting (XSS) in OAuth Device Authorization screen | hexpm | 8.5 (v4.0) | High |
| CVE-2026-34932 | hoppscotch: Stored XSS via mock server responses on backend origin | hoppscotch | 8.5 (v4.0) | High |
| CVE-2026-58113 | Teamcenter V2412 Cross-site Scripting Vulnerability | Teamcenter V2412 | 8.5 (v4.0) | High |
| CVE-2026-63361 | LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup | LimeSurvey | 8.5 (v4.0) | High |
| CVE-2026-64851 | Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers | grav-plugin-shortcode-core | 8.5 (v4.0) | High |
| CVE-2026-65986 | CVAT has stored XSS via annotation guide assets | cvat | 8.5 (v4.0) | High |
| CVE-2026-75933 | Jet Admin Stored XSS | Jet Admin | 8.5 (v4.0) | High |
| CVE-2026-15973 | LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries | LimeSurvey | 8.4 (v4.0) | High |
| CVE-2026-5385 | GLPI 11.0.0 - Stored XSS in knowledge base | glpi | 8.4 (v4.0) | High |
| CVE-2026-77072 | n8n before 1.123.69 Stored XSS via Form Completion Page | n8n | 8.4 (v4.0) | High |
| CVE-2026-77850 | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content | ash admin | 8.4 (v4.0) | High |
| CVE-2026-85613 | OpenPanel Unauthenticated XSS via SVG Favicon Proxy | openpanel | 8.4 (v4.0) | High |
| CVE-2026-87814 | SiYuan before v3.8.2 Stored XSS via Asset Preview | siyuan | 8.4 (v4.0) | High |
| CVE-2017-10075 | Oracle Content Server - Cross-Site Scripting | webcenter content | 8.2 (v3.0) | High |
| CVE-2026-34725 | dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration | dbgate | 8.2 (v3.1) | High |
| CVE-2026-56670 | ComfyUI: Stored XSS via SVG file upload on the /view endpoint | ComfyUI | 8.2 (v3.1) | High |
| CVE-2026-63135 | YOURLS: Stored XSS in referrer statistics chart via crafted Referer header | YOURLS | 8.2 (v3.1) | High |
| CVE-2016-1337 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 8.1 (v3.0) | High |
| CVE-2018-6221 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.1 (v3.0) | High |
| CVE-2026-18147 | Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url | Red Hat Enterprise Linux 10 | 8.1 (v3.1) | High |
| CVE-2026-33437 | Stirling PDF: Stored XSS in Info Summary | Stirling-PDF | 8.1 (v3.1) | High |
| CVE-2026-39344 | Reflected XSS the login page through the 'username' parameter | churchcrm | 8.1 (v3.0) | High |
| CVE-2026-48060 | Litestar: HTML Injection Through CSRF Token | litestar | 8.1 (v3.1) | High |
| CVE-2026-48081 | OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer | appointment-booking-software | 8.1 (v3.1) | High |
| CVE-2026-50758 | DayuanJiang next-ai-draw-io 0.4.13 Arbitrary Code Execution Vulnerability | DayuanJiang next-ai-draw-io 0.4.13 | 8.1 (v3.1) | High |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 (v3.0) | High |
| CVE-2018-6222 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 7.8 (v3.0) | High |
| CVE-2026-16969 | DFIR-IRIS Stored XSS in Assets | iris-web | 7.6 (v3.1) | High |
| CVE-2026-18360 | DFIR-IRIS Stored XSS in Custom Attributes | iris-web | 7.6 (v3.1) | High |
| CVE-2026-18361 | DFIR-IRIS Stored XSS in Datastore Upload | iris-web | 7.6 (v3.1) | High |
| CVE-2013-6041 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 7.5 (v2.0) | High |
| CVE-2015-6401 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 7.5 (v2.0) | High |
| CVE-2016-1328 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2016-1336 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2026-12592 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | SlimStat Analytics | 7.5 (v3.1) | High |
| CVE-2026-44657 | MantisBT: Stored XSS in File Download | mantisbt | 7.5 (v4.0) | High |
| CVE-2026-7460 | mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped | mailcow-dockerized | 7.4 (v4.0) | High |
| CVE-2026-87812 | SiYuan before v3.8.2 Stored XSS via Bazaar iconURL | siyuan | 7.4 (v4.0) | High |
| CVE-2026-30819 | Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter | iTop | 7.3 (v3.1) | High |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | php | 7.3 (v4.0) | High |
| CVE-2026-8203 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter | concrete cms | 7.3 (v4.0) | High |
| CVE-2026-16809 | LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering | LimeSurvey | 7.2 (v4.0) | High |
| CVE-2026-18430 | HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason | HumHub | 7.2 (v4.0) | High |
| CVE-2026-18756 | HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering | HumHub | 7.2 (v4.0) | High |
| CVE-2026-4267 | Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URI | Query Monitor | 7.2 (v3.1) | High |
| CVE-2022-35499 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint Cross-Site Scripting Vulnerability | - | 7.1 (v3.1) | High |
| CVE-2026-12970 | LearnPress < 4.4.1 - Reflected XSS via c_search | LearnPress | 7.1 (v3.1) | High |
| CVE-2026-14239 | Tourmaster < 5.4.8 - Stored XSS via CSRF | tourmaster | 7.1 (v3.1) | High |
| CVE-2026-34598 | YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" | yeswiki | 7.1 (v4.0) | High |
| CVE-2026-6858 | Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS | Transbank Webpay | 7.1 (v3.1) | High |
| CVE-2026-84192 | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data | librenms | 7.1 (v4.0) | High |
| CVE-2026-55746 | Cotonti stored XSS via PFS folder title | Cotonti | 7.0 (v4.0) | High |
| CVE-2026-58411 | ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values | CRM | 7.0 (v4.0) | High |
| CVE-2026-80426 | FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Description | fiftyone | 7.0 (v4.0) | High |
| CVE-2025-4388 | Liferay Portal - Cross-Site Scripting | digital experience platform | 6.9 (v4.0) | Medium |
| CVE-2025-62613 | VDO.Ninja - DOM-Based Cross-Site Scripting | vdo.ninja | 6.9 (v4.0) | Medium |
| CVE-2026-39838 | ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS | MediaWiki - ProofreadPage Extension | 6.9 (v4.0) | Medium |
| CVE-2026-39936 | Stored XSS in Score due to usage of non-reserved data attributes | Mediawiki - Score Extension | 6.9 (v4.0) | Medium |
| CVE-2026-40598 | MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page | mantisbt | 6.9 (v4.0) | Medium |
| CVE-2026-44651 | SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware | SillyTavern | 6.9 (v4.0) | Medium |
| CVE-2026-59238 | Stored XSS in Pentestify via unsanitized finding images and report client logo | Pentestify | 6.9 (v4.0) | Medium |
| CVE-2026-69092 | Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint | admidio | 6.9 (v4.0) | Medium |
| CVE-2026-73848 | Emlog: Stored XSS via Tag Name in Article Editor | emlog | 6.9 (v4.0) | Medium |
| CVE-2026-86188 | AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting | AVideo | 6.9 (v4.0) | Medium |
| CVE-2018-6230 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.8 (v3.0) | Medium |
| CVE-2026-13605 | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute | PhotoSwipe | 6.8 (v3.1) | Medium |
| CVE-2026-14817 | Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes | Element Pack Addons for Elementor | 6.8 (v3.1) | Medium |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | Calendar | 6.8 (v3.1) | Medium |
| CVE-2026-14833 | Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute | Lightbox with PhotoSwipe | 6.8 (v3.1) | Medium |
| CVE-2026-15047 | s2Member < 260805 - Contributor+ Stored XSS via Shortcode | s2Member | 6.8 (v3.1) | Medium |
| CVE-2026-16559 | YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload | YMC Filter | 6.8 (v3.1) | Medium |
| CVE-2026-33741 | EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript | espocrm | 6.8 (v3.1) | Medium |
| CVE-2026-39311 | Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments | Trilium | 6.8 (v3.1) | Medium |
| CVE-2026-67352 | luci-app-https-dns-proxy Stored XSS via resolver_url | luci | 6.8 (v4.0) | Medium |
| CVE-2018-1203 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2018-1204 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2018-6219 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.5 (v3.0) | Medium |
| CVE-2025-32430 | XWiki Platform - Cross-Site Scripting | xwiki-platform | 6.5 (v4.0) | Medium |
| CVE-2025-61224 | DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scripting | dokuwiki | 6.5 (v3.1) | Medium |
| CVE-2026-24128 | XWiki Platform Distribution Flavor Main - Cross-Site Scripting | xwiki-platform-distribution-flavor-main | 6.5 (v4.0) | Medium |
| CVE-2026-55549 | Yamcs: Reflected XSS in the URL of the Authorize Endpoint | yamcs | 6.5 (v3.1) | Medium |
| CVE-2026-78838 | AppNitro MachForm v30 Cross-Site Scripting Vulnerability | AppNitro MachForm v30 | 6.5 (v3.1) | Medium |
| CVE-2026-0737 | Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode | WP Shortcodes Plugin — Shortcodes Ultimate | 6.4 (v3.1) | Medium |
| CVE-2026-0738 | Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode | WP Shortcodes Plugin — Shortcodes Ultimate | 6.4 (v3.1) | Medium |
| CVE-2026-3885 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_bo | Shortcodes Ultimate – Content Elements | 6.4 (v3.1) | Medium |
| CVE-2026-45797 | HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload | heyform | 6.4 (v4.0) | Medium |
| CVE-2026-50592 | Znuny Cross-Site Scripting Vulnerability | Znuny | 6.4 (v3.1) | Medium |
| CVE-2026-87870 | Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Paramete | Ninja Forms - Scheduled Exports | 6.4 (v3.1) | Medium |
| CVE-2026-43980 | Malla: Stored XSS via Meshtastic node names in multiple frontend pages | malla | 6.3 (v3.1) | Medium |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 (v3.0) | Medium |
| CVE-2016-15041 | MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting | mainwp dashboard | 6.1 (v3.1) | Medium |
| CVE-2016-8527 | Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting | airwave | 6.1 (v3.0) | Medium |
| CVE-2017-12583 | DokuWiki - Cross-Site Scripting | dokuwiki | 6.1 (v3.0) | Medium |
| CVE-2017-7855 | IceWarp WebMail 11.3.1.5 - Cross-Site Scripting | server | 6.1 (v3.0) | Medium |
| CVE-2017-9140 | Reflected XSS - Telerik Reporting Module | telerik reporting | 6.1 (v3.0) | Medium |
| CVE-2018-10383 | Lantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site Scripting | securelinx spider firmware | 6.1 (v3.0) | Medium |
| CVE-2018-11227 | Monstra CMS <=3.0.4 - Cross-Site Scripting | monstra cms | 6.1 (v3.0) | Medium |
| CVE-2018-13380 | Fortinet FortiOS - Cross-Site Scripting | fortios | 6.1 (v3.1) | Medium |
| CVE-2018-16833 | ManageEngine Desktop Central 10.0.271 - Cross-Site Scripting | manageengine desktop central | 6.1 (v3.0) | Medium |
| CVE-2018-19287 | WordPress Ninja Forms <3.3.18 - Cross-Site Scripting | ninja forms | 6.1 (v3.0) | Medium |
| CVE-2018-6882 | zimbra collaboration suite Cross-Site Scripting Vulnerability | zimbra collaboration suite | 6.1 (v3.1) | Medium |
| CVE-2018-7653 | YzmCMS v3.6 - Cross-Site Scripting | yzmcms | 6.1 (v3.0) | Medium |
| CVE-2019-10475 | Jenkins build-metrics 1.3 - Cross-Site Scripting | build-metrics | 6.1 (v3.1) | Medium |
| CVE-2019-11507 | Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected) | connect secure | 6.1 (v3.1) | Medium |
| CVE-2019-14470 | WordPress UserPro 4.9.32 - Cross-Site Scripting | instagram-php-api | 6.1 (v3.0) | Medium |
| CVE-2019-15811 | DomainMOD <=4.13.0 - Cross-Site Scripting | domainmod | 6.1 (v3.0) | Medium |
| CVE-2019-20141 | WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting | neon | 6.1 (v3.1) | Medium |
| CVE-2020-1106 | Microsoft Office SharePoint XSS Vulnerability | sharepoint enterprise server | 6.1 (v3.1) | Medium |
| CVE-2020-12054 | WordPress Catch Breadcrumb <1.5.4 - Cross-Site Scripting | catch breadcrumb | 6.1 (v3.1) | Medium |
| CVE-2020-13820 | Extreme Management Center 8.4.1.24 - Cross-Site Scripting | extreme management center | 6.1 (v3.1) | Medium |
| CVE-2020-14413 | NeDi 1.9C - Cross-Site Scripting | nedi | 6.1 (v3.1) | Medium |
| CVE-2020-15500 | TileServer GL <=3.0.0 - Cross-Site Scripting | tileservergl | 6.1 (v3.1) | Medium |
| CVE-2020-15718 | RosarioSIS 6.7.2 - Cross-Site Scripting | rosariosis | 6.1 (v3.1) | Medium |
| CVE-2020-23814 | XXL-JOB v2.2.0 — Stored Cross Site Scripting | xxl-job | 6.1 (v3.1) | Medium |
| CVE-2020-27982 | IceWarp WebMail 11.4.5.0 - Cross-Site Scripting | mail server | 6.1 (v3.1) | Medium |
| CVE-2020-29164 | PacsOne Server <7.1.1 - Cross-Site Scripting | pacsone server | 6.1 (v3.1) | Medium |
| CVE-2020-29395 | Wordpress EventON Calendar 3.0.5 - Cross-Site Scripting | eventon | 6.1 (v3.1) | Medium |
| CVE-2020-3580 | Cisco ASA/FTD Software - Cross-Site Scripting | firepower threat defense | 6.1 (v3.1) | Medium |
| CVE-2020-7107 | WordPress Ultimate FAQ <1.8.30 - Cross-Site Scripting | ultimate faq | 6.1 (v3.1) | Medium |
| CVE-2020-8512 | IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting | icewarp server | 6.1 (v3.1) | Medium |
| CVE-2021-20137 | Gryphon Tower - Cross-Site Scripting | gryphon tower | 6.1 (v3.1) | Medium |
| CVE-2021-20323 | Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting | keycloak | 6.1 (v3.1) | Medium |
| CVE-2021-21801 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 (v3.1) | Medium |
| CVE-2021-21802 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 (v3.1) | Medium |
| CVE-2021-21803 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 (v3.1) | Medium |
| CVE-2021-24235 | WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting | goto | 6.1 (v3.1) | Medium |
| CVE-2021-24237 | WordPress Realteo <=1.2.3 - Cross-Site Scripting | findeo | 6.1 (v3.1) | Medium |
| CVE-2021-24245 | WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS) | stop spammers | 6.1 (v3.1) | Medium |
| CVE-2021-24300 | WordPress WooCommerce <1.13.22 - Cross-Site Scripting | product slider for woocommerce | 6.1 (v3.1) | Medium |
| CVE-2021-24435 | WordPress Titan Framework plugin <= 1.12.1 - Cross-Site Scripting | titan framework | 6.1 (v3.1) | Medium |
| CVE-2021-24488 | WordPress Post Grid <2.1.8 - Cross-Site Scripting | post grid | 6.1 (v3.1) | Medium |
| CVE-2021-24495 | Wordpress Marmoset Viewer <1.9.3 - Cross-Site Scripting | marmoset viewer | 6.1 (v3.1) | Medium |
| CVE-2021-24498 | WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scripting | calendar event multi view | 6.1 (v3.1) | Medium |
| CVE-2021-24875 | WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scripting | ecommerce product catalog | 6.1 (v3.1) | Medium |
| CVE-2021-26947 | Odoo <= 15.0 - Cross-Site Scripting | odoo | 6.1 (v3.1) | Medium |
| CVE-2021-27519 | FUDForum 3.1.0 - Cross-Site Scripting | fudforum | 6.1 (v3.1) | Medium |
| CVE-2021-27520 | FUDForum 3.1.0 - Cross-Site Scripting | fudforum | 6.1 (v3.1) | Medium |
| CVE-2021-27695 | openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting | openmaint | 6.1 (v3.1) | Medium |
| CVE-2021-3002 | Seo Panel 4.8.0 - Cross-Site Scripting | seo panel | 6.1 (v3.1) | Medium |
| CVE-2021-30134 | Php-mod/curl Library <2.3.2 - Cross-Site Scripting | php curl class | 6.1 (v3.1) | Medium |
| CVE-2021-30203 | Dzzoffice 2.02.1 - Cross-Site Scripting | dzzoffice | 6.1 (v3.1) | Medium |
| CVE-2021-31589 | BeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site Scripting | appliance base software | 6.1 (v3.1) | Medium |
| CVE-2021-33829 | Drupal 7 CKEditor XSS | ckeditor | 6.1 (v3.1) | Medium |
| CVE-2021-42567 | Apereo CAS Cross-Site Scripting | central authentication service | 6.1 (v3.1) | Medium |
| CVE-2021-43062 | Fortinet FortiMail 7.0.1 - Cross-Site Scripting | fortimail | 6.1 (v3.1) | Medium |
| CVE-2021-46387 | Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS) | zywall 2 plus internet security appliance firmware | 6.1 (v3.1) | Medium |
| CVE-2022-0201 | WordPress Permalink Manager <2.2.15 - Cross-Site Scripting | permalink manager lite | 6.1 (v3.1) | Medium |
| CVE-2022-0208 | WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting | mappress | 6.1 (v3.1) | Medium |
| CVE-2022-0346 | WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Execution | xml sitemap generator | 6.1 (v3.1) | Medium |
| CVE-2022-0533 | Ditty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scripting | ditty | 6.1 (v3.1) | Medium |
| CVE-2022-0879 | Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting | caldera forms | 6.1 (v3.1) | Medium |
| CVE-2022-1168 | WordPress WP JobSearch <1.5.1 - Cross-Site Scripting | jobsearch wp job board | 6.1 (v3.1) | Medium |
| CVE-2022-1170 | JobMonster < 4.5.2.9 - Cross-Site Scripting | jobmonster | 6.1 (v3.1) | Medium |
| CVE-2022-23397 | Cedar Gate EZ-NET <= 6.8.0 - Cross-Site Scripting | ez-net portal | 6.1 (v3.1) | Medium |
| CVE-2022-24384 | SmarterTools SmarterTrack - Cross-Site Scripting | smartertrack | 6.1 (v3.1) | Medium |
| CVE-2022-2733 | Openemr < 7.0.0.1 - Cross-Site Scripting | openemr | 6.1 (v3.1) | Medium |
| CVE-2022-27926 | Zimbra Collaboration (ZCS) - Cross Site Scripting | collaboration | 6.1 (v3.1) | Medium |
| CVE-2022-28363 | Reprise License Manager 14.2 - Cross-Site Scripting | reprise license manager | 6.1 (v3.1) | Medium |
| CVE-2022-3062 | Simple File List < 4.4.12 - Cross Site Scripting | simple-file-list | 6.1 (v3.1) | Medium |
| CVE-2022-30983 | Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 Cross-Site Scripting Vulnerability | Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 | 6.1 (v3.1) | Medium |
| CVE-2022-31798 | Nortek Linear eMerge E3-Series - Cross-Site Scripting | emerge e3 firmware | 6.1 (v3.1) | Medium |
| CVE-2022-32195 | Open edX <2022-06-06 - Cross-Site Scripting | open edx | 6.1 (v3.1) | Medium |
| CVE-2022-35493 | eShop 3.0.4 - Cross-Site Scripting | eshop - ecommerce / store website | 6.1 (v3.1) | Medium |
| CVE-2022-35653 | Moodle LTI module Reflected - Cross-Site Scripting | moodle | 6.1 (v3.1) | Medium |
| CVE-2022-3766 | phpMyFAQ < 3.1.8 - Cross-Site Scripting | phpmyfaq | 6.1 (v3.1) | Medium |
| CVE-2022-38467 | CRM Perks Forms < 1.1.1 - Cross Site Scripting | crm perks forms | 6.1 (v3.1) | Medium |
| CVE-2022-45836 | WordPress Download Manager <= 3.2.59 - Reflected XSS | download manager | 6.1 (v3.1) | Medium |
| CVE-2022-46381 | Linear eMerge E3-Series - Cross-Site Scripting | linear emerge e3 access control firmware | 6.1 (v3.1) | Medium |
| CVE-2023-0099 | Simple URLs < 115 - Cross Site Scripting | simple urls | 6.1 (v3.1) | Medium |
| CVE-2023-0236 | WordPress Tutor LMS <2.0.10 - Cross Site Scripting | tutor lms | 6.1 (v3.1) | Medium |
| CVE-2023-0527 | Online Security Guards Hiring System - Cross-Site Scripting | online security guards hiring system | 6.1 (v3.1) | Medium |
| CVE-2023-1780 | Companion Sitemap Generator < 4.5.3 - Cross-Site Scripting | companion sitemap generator | 6.1 (v3.1) | Medium |
| CVE-2023-23161 | Art Gallery Management System Project v1.0 - Cross-Site Scripting | art gallery management system | 6.1 (v3.1) | Medium |
| CVE-2023-2813 | Wordpress Multiple Themes - Reflected Cross-Site Scripting | connections reloaded | 6.1 (v3.1) | Medium |
| CVE-2023-2822 | Ellucian Ethos Identity CAS - Cross-Site Scripting | ethos identity | 6.1 (v3.1) | Medium |
| CVE-2023-2949 | OpenEMR < 7.0.1 - Cross-site Scripting | openemr | 6.1 (v3.1) | Medium |
| CVE-2023-29623 | Purchase Order Management v1.0 - Cross Site Scripting (Reflected) | purchase order management | 6.1 (v3.1) | Medium |
| CVE-2023-30256 | Webkul QloApps 1.5.2 - Cross-site Scripting | qloapps | 6.1 (v3.1) | Medium |
| CVE-2023-30777 | Advanced Custom Fields < 6.1.6 - Cross-Site Scripting | advanced custom fields | 6.1 (v3.1) | Medium |
| CVE-2023-35155 | XWiki - Cross-Site Scripting | xwiki | 6.1 (v3.1) | Medium |
| CVE-2023-3521 | FOSSBilling < 0.5.3 - Cross-Site Scripting | fossbilling | 6.1 (v3.1) | Medium |
| CVE-2023-36289 | Webkul QloApps 1.6.0 - Cross-site Scripting | qloapps | 6.1 (v3.1) | Medium |
| CVE-2023-37580 | Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting | zimbra | 6.1 (v3.1) | Medium |
| CVE-2023-37728 | IceWarp Webmail Server v10.2.1 - Cross Site Scripting | icewarp | 6.1 (v3.1) | Medium |
| CVE-2023-38194 | SuperWebMailer - Cross-Site Scripting | superwebmailer | 6.1 (v3.1) | Medium |
| CVE-2023-38501 | CopyParty v1.8.6 - Cross Site Scripting | copyparty | 6.1 (v3.1) | Medium |
| CVE-2023-38910 | CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' ) | csz cms | 6.1 (v3.1) | Medium |
| CVE-2023-38964 | Academy LMS 6.0 - Cross-Site Scripting | academy lms | 6.1 (v3.1) | Medium |
| CVE-2023-39598 | IceWarp Email Client - Cross Site Scripting | webclient | 6.1 (v3.1) | Medium |
| CVE-2023-39600 | IceWarp 11.4.6.0 - Cross-Site Scripting | icewarp | 6.1 (v3.1) | Medium |
| CVE-2023-39700 | IceWarp Mail Server v10.4.5 - Cross-Site Scripting | mail server | 6.1 (v3.1) | Medium |
| CVE-2023-40750 | PHPJabbers Yacht Listing Script v1.0 - Cross-Site Scripting | yacht listing script | 6.1 (v3.1) | Medium |
| CVE-2023-40751 | PHPJabbers Fundraising Script v1.0 - Cross-Site Scripting | fundraising script | 6.1 (v3.1) | Medium |
| CVE-2023-40752 | PHPJabbers Make an Offer Widget v1.0 - Cross-Site Scripting | make an offer widget | 6.1 (v3.1) | Medium |
| CVE-2023-4174 | mooSocial 3.1.6 - Reflected Cross Site Scripting | moostore | 6.1 (v3.1) | Medium |
| CVE-2023-42343 | OpenCMS - Cross-Site Scripting | opencms | 6.1 (v3.1) | Medium |
| CVE-2023-44012 | mojoPortal v.2.7.0.0 - Cross-Site Scripting | mojoportal | 6.1 (v3.1) | Medium |
| CVE-2023-46020 | Blood Bank v1.0 - Stored Cross Site Scripting (XSS) | blood bank | 6.1 (v3.1) | Medium |
| CVE-2023-49494 | DedeCMS v5.7.111 - Cross-Site Scripting | dedecms | 6.1 (v3.1) | Medium |
| CVE-2023-5758 | firefox mobile Cross-Site Scripting Vulnerability | firefox mobile | 6.1 (v3.1) | Medium |
| CVE-2023-5863 | phpMyFAQ < 3.2.0 - Cross-site Scripting | phpmyfaq | 6.1 (v3.1) | Medium |
| CVE-2024-30194 | Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting | sunshine photo cart | 6.1 (v3.1) | Medium |
| CVE-2024-35693 | WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting | 12 step meeting list | 6.1 (v3.1) | Medium |
| CVE-2024-55218 | IceWarp Server 10.2.1 - Cross-Site Scripting | mail server | 6.1 (v3.1) | Medium |
| CVE-2024-6892 | Journyx 11.5.4 - Reflected Cross Site Scripting | journyx | 6.1 (v3.1) | Medium |
| CVE-2025-25296 | Label Studio < 1.16.0 - Cross-Site Scripting | label studio | 6.1 (v3.1) | Medium |
| CVE-2025-2609 | MagnusBilling Login Logs - Cross-Site Scripting | magnusbilling | 6.1 (v3.1) | Medium |
| CVE-2025-46349 | YesWiki Reflected XSS via File Upload | yeswiki | 6.1 (v3.1) | Medium |
| CVE-2025-48954 | Discourse OAuth Social Login - Cross-site Scripting | discourse | 6.1 (v3.1) | Medium |
| CVE-2025-54597 | Heimdall Application Dashboard < 2.7.3 - Reflected XSS | heimdall | 6.1 (v3.1) | Medium |
| CVE-2025-63607 | TechStore 1.0 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2025-65341 | Ecommerce Fruits Bazar 1.0 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-0594 | WordPress List Site Contributors < 1.1.8 - Reflected XSS | List Site Contributors | 6.1 (v3.1) | Medium |
| CVE-2026-11588 | EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation | EONSR AEO Agent | 6.1 (v3.1) | Medium |
| CVE-2026-11881 | Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field | Fluent Forms | 6.1 (v3.1) | Medium |
| CVE-2026-13330 | Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload | Animation Addons for Elementor | 6.1 (v3.1) | Medium |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information | Simply Schedule Appointments | 6.1 (v3.1) | Medium |
| CVE-2026-14921 | Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode | Ultimate Addons for WPBakery Page Builder | 6.1 (v3.1) | Medium |
| CVE-2026-17505 | WordPress TranslatePress < 3.2.6 - Cross-Site Scripting | translatepress-multilingual | 6.1 (v3.1) | Medium |
| CVE-2026-26028 | CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS | cryptpad | 6.1 (v3.1) | Medium |
| CVE-2026-30251 | zenshare suite Cross-Site Scripting Vulnerability | zenshare suite | 6.1 (v3.1) | Medium |
| CVE-2026-30252 | zencrm Cross-Site Scripting Vulnerability | zencrm | 6.1 (v3.1) | Medium |
| CVE-2026-34206 | Captcha Protect: Reflected XSS in challenge page via unsanitized destination rendered with text/template | captcha protect | 6.1 (v3.1) | Medium |
| CVE-2026-34229 | Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass | emlog | 6.1 (v3.1) | Medium |
| CVE-2026-34396 | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel | avideo | 6.1 (v3.1) | Medium |
| CVE-2026-34739 | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php | avideo | 6.1 (v3.1) | Medium |
| CVE-2026-36324 | SourceCodester Doctor Appointment System 1.0 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-37750 | School Management System by mahmoudai1 Cross-Site Scripting Vulnerability | School Management System by mahmoudai1 | 6.1 (v3.1) | Medium |
| CVE-2026-38432 | erpnext Cross-Site Scripting Vulnerability | erpnext | 6.1 (v3.1) | Medium |
| CVE-2026-38444 | osTicket v1.18.3 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-38446 | Cross-Site Scripting | - | 6.1 (v3.1) | Medium |
| CVE-2026-38472 | forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability | forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 6.1 (v3.1) | Medium |
| CVE-2026-38947 | FluentCMS 1.2.3 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-41580 | Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author) | stirling pdf | 6.1 (v3.1) | Medium |
| CVE-2026-42253 | Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties | activemq | 6.1 (v3.1) | Medium |
| CVE-2026-51565 | Modules/Docs/DocsController.php in Milk admin <=0.9.8 Cross-Site Scripting Vulnerability | Modules/Docs/DocsController.php in Milk admin <=0.9.8 | 6.1 (v3.1) | Medium |
| CVE-2026-52232 | FS Inc S3150-8T2F Switch 2.2.0D Build 118101 Cross-Site Scripting Vulnerability | FS Inc S3150-8T2F Switch 2.2.0D Build 118101 | 6.1 (v3.1) | Medium |
| CVE-2026-52475 | aiflowy <= 2.1.2 Cross-Site Scripting Vulnerability | aiflowy <= 2.1.2 | 6.1 (v3.1) | Medium |
| CVE-2026-52774 | YesWiki Bazar Widget - Reflected XSS via 'id' Parameter | yeswiki | 6.1 (v3.1) | Medium |
| CVE-2026-55087 | Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (ope | etherpad | 6.1 (v3.1) | Medium |
| CVE-2026-5776 | Email Encoder < 2.4.7 - Unauthenticated Stored XSS | Email Encoder | 6.1 (v3.1) | Medium |
| CVE-2026-61526 | AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler | http-server | 6.1 (v3.1) | Medium |
| CVE-2026-73084 | Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint | activepieces | 6.1 (v3.1) | Medium |
| CVE-2026-75170 | the HubCore platform (version 14.1.1) Cross-Site Scripting Vulnerability | the HubCore platform (version 14.1.1) | 6.1 (v3.1) | Medium |
| CVE-2026-75307 | zhitan-ems 1.0.0 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-78742 | Silverpeas Core <=6.4.6 Cross-Site Scripting Vulnerability | - | 6.1 (v3.1) | Medium |
| CVE-2026-8447 | Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untruste | langflow | 6.1 (v3.1) | Medium |
| CVE-2023-6717 | Keycloak: xss via assertion consumer service url in saml post-binding flow | Red Hat AMQ Broker 7 | 6.0 (v3.1) | Medium |
| CVE-2026-8245 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection | concrete cms | 6.0 (v4.0) | Medium |
| CVE-2026-63428 | HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's dec | heyform | 5.8 (v3.1) | Medium |
| CVE-2026-84193 | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP | librenms | 5.8 (v4.0) | Medium |
| CVE-2026-88055 | AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator | anything-llm | 5.5 (v3.1) | Medium |
| CVE-2018-6226 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2018-6227 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2020-11456 | LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting | limesurvey | 5.4 (v3.1) | Medium |
| CVE-2020-11457 | pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting | pfsense | 5.4 (v3.1) | Medium |
| CVE-2020-20285 | ZZcms - Cross-Site Scripting | zzcms | 5.4 (v3.1) | Medium |
| CVE-2020-24963 | Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated) | best support system | 5.4 (v3.1) | Medium |
| CVE-2021-25067 | Landing Page Builder < 1.4.9.6 - Cross-Site Scripting | landing page | 5.4 (v3.1) | Medium |
| CVE-2021-35956 | AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS) | sensorprobe2 firmware | 5.4 (v3.1) | Medium |
| CVE-2022-0020 | Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS) | cortex xsoar | 5.4 (v3.1) | Medium |
| CVE-2022-0378 | Microweber Cross-Site Scripting | microweber | 5.4 (v3.1) | Medium |
| CVE-2022-0928 | Microweber < 1.2.12 - Stored Cross-Site Scripting | microweber | 5.4 (v3.1) | Medium |
| CVE-2022-0954 | Microweber <1.2.11 - Stored Cross-Site Scripting | microweber | 5.4 (v3.1) | Medium |
| CVE-2023-26842 | ChurchCRM 4.5.3 - Cross-Site Scripting | churchcrm | 5.4 (v3.1) | Medium |
| CVE-2023-26843 | ChurchCRM 4.5.3 - Cross-Site Scripting | churchcrm | 5.4 (v3.1) | Medium |
| CVE-2023-31548 | ChurchCRM v4.5.3 - Cross-Site Scripting | churchcrm | 5.4 (v3.1) | Medium |
| CVE-2023-38911 | CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery') | csz cms | 5.4 (v3.1) | Medium |
| CVE-2024-52763 | Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting | ganglia-web | 5.4 (v3.1) | Medium |
| CVE-2025-2610 | MagnusBilling Alarm Module - Cross-Site Scripting | magnusbilling | 5.4 (v3.1) | Medium |
| CVE-2026-11569 | Quay: quay: stored xss via filedrop svg upload | Red Hat Quay 3 | 5.4 (v3.1) | Medium |
| CVE-2026-15245 | BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode | BNE Testimonials | 5.4 (v3.1) | Medium |
| CVE-2026-15262 | Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column | Admin Columns for ACF Fields | 5.4 (v3.1) | Medium |
| CVE-2026-16063 | Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content | Event Booking Manager for WooCommerce | 5.4 (v3.1) | Medium |
| CVE-2026-16537 | Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode | Slick Slider | 5.4 (v3.1) | Medium |
| CVE-2026-16558 | YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema | YMC Filter | 5.4 (v3.1) | Medium |
| CVE-2026-18395 | Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes | Child Pages Card | 5.4 (v3.1) | Medium |
| CVE-2026-34848 | hoppscotch: Stored XSS in team member overflow tooltip via display name | hoppscotch | 5.4 (v3.1) | Medium |
| CVE-2026-34974 | phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation | phpmyfaq | 5.4 (v3.1) | Medium |
| CVE-2026-35403 | LORIS has potential cross-site scripting in survey_accounts module | loris | 5.4 (v3.1) | Medium |
| CVE-2026-35455 | immich has Stored XSS via OCR Text in 360° Panorama Viewer | immich | 5.4 (v3.1) | Medium |
| CVE-2026-36392 | FairSketch Rise CRM Version 3.9.6 Cross-Site Scripting Vulnerability | - | 5.4 (v3.1) | Medium |
| CVE-2026-38473 | the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability | the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 5.4 (v3.1) | Medium |
| CVE-2026-39380 | Open Source Point of Sale has Stored XSS in Stock Location (Configuration) | open source point of sale | 5.4 (v3.1) | Medium |
| CVE-2026-39964 | TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers | typebot.io | 5.4 (v3.1) | Medium |
| CVE-2026-45138 | CI4MS: Stored XSS in Blog Content via Broken html_purify Validation Rule | ci4ms | 5.4 (v3.1) | Medium |
| CVE-2026-45580 | WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute | avideo | 5.4 (v3.1) | Medium |
| CVE-2026-45694 | LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters | librenms | 5.4 (v3.1) | Medium |
| CVE-2026-72570 | cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename | directory-serve | 5.4 (v3.1) | Medium |
| CVE-2026-72583 | fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload | fastschema | 5.4 (v3.1) | Medium |
| CVE-2026-82396 | Sulu: Stored XSS via media download inline-disposition override | sulu | 5.4 (v3.1) | Medium |
| CVE-2026-9278 | Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure | Form Builder CP | 5.4 (v3.1) | Medium |
| CVE-2019-25731 | Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact | Zuz Music | 5.3 (v4.0) | Medium |
| CVE-2023-30943 | Moodle - Cross-Site Scripting/Remote Code Execution | moodle | 5.3 (v3.1) | Medium |
| CVE-2025-2709 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | 5.3 (v4.0) | Medium |
| CVE-2025-2711 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | 5.3 (v4.0) | Medium |
| CVE-2025-2712 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida erp-nc | 5.3 (v4.0) | Medium |
| CVE-2026-25860 | OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler | OpenClinic GA | 5.3 (v4.0) | Medium |
| CVE-2026-35208 | lichess.org has an Unsanitized Stream Title Injection on /streamer | lila | 5.3 (v4.0) | Medium |
| CVE-2026-48094 | ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output | shareopenly | 5.3 (v4.0) | Medium |
| CVE-2026-5808 | openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scripting | openstatus | 5.3 (v4.0) | Medium |
| CVE-2026-59232 | Stored Cross-site Scripting in Prospero Flow CRM lead name field | Prospero Flow CRM | 5.3 (v4.0) | Medium |
| CVE-2026-69116 | FlyEnv < 4.18.0 Cross-Site Scripting via v-html | FlyEnv | 5.3 (v4.0) | Medium |
| CVE-2026-73038 | NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name | NodeBB | 5.3 (v4.0) | Medium |
| CVE-2026-73422 | Astro: Reflected XSS via unescaped View Transition animation properties | astro | 5.3 (v4.0) | Medium |
| CVE-2026-73628 | Serendipity 2.3.5 Reflected XSS via search clean-URL route | Serendipity | 5.3 (v4.0) | Medium |
| CVE-2026-76837 | Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display Name | Baserow | 5.3 (v4.0) | Medium |
| CVE-2026-82451 | Formwork through 2.3.14 Stored XSS via Referer Header | Formwork | 5.3 (v4.0) | Medium |
| CVE-2026-82646 | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-84191 | LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields | librenms | 5.3 (v4.0) | Medium |
| CVE-2026-85158 | AVideo Reflected XSS via videoEmbeded.php link parameter | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-85159 | AVideo Reflected XSS via cancelUri in userLogin.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-85577 | AVideo userLogin.php Reflected XSS via error parameter | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-89240 | WWBN AVideo Reflected XSS via confirmLivePassword.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-89241 | WWBN AVideo Reflected XSS via confirmLivePassword.php | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-89244 | WWBN AVideo Reflected XSS via Gallery Category getBackURL | AVideo | 5.3 (v4.0) | Medium |
| CVE-2018-25248 | MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php | mybb downloads | 5.1 (v4.0) | Medium |
| CVE-2018-25349 | userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header | userSpice | 5.1 (v4.0) | Medium |
| CVE-2019-25739 | GigToDo Freelance Marketplace Script 1.3 Persistent XSS | GigToDo | 5.1 (v4.0) | Medium |
| CVE-2021-47931 | Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication | Exponent CMS | 5.1 (v4.0) | Medium |
| CVE-2021-47947 | Projectsend r1295 Stored Cross-Site Scripting via files-edit.php | Projectsend | 5.1 (v4.0) | Medium |
| CVE-2022-50943 | Moodle LMS 4.0 Cross-Site Scripting via course search.php | moodle | 5.1 (v4.0) | Medium |
| CVE-2022-50948 | Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting | Motopress Hotel Booking Lite | 5.1 (v4.0) | Medium |
| CVE-2022-50958 | WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php | Jetpack | 5.1 (v4.0) | Medium |
| CVE-2022-50959 | WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php | Contact Form Builder | 5.1 (v4.0) | Medium |
| CVE-2022-50961 | WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS | IP2Location Country Blocker | 5.1 (v4.0) | Medium |
| CVE-2022-50962 | uBidAuction 2.0.1 myOrders Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50963 | uBidAuction 2.0.1 myAuctions active Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50964 | uBidAuction 2.0.1 myAuctions loose Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50965 | uBidAuction 2.0.1 posts manage Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50966 | uBidAuction 2.0.1 news manage Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50968 | uBidAuction 2.0.1 auctions manage Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2022-50969 | uBidAuction 2.0.1 mailingLog manage Reflected XSS | uBidAuction | 5.1 (v4.0) | Medium |
| CVE-2025-34141 | ETQ Reliance - Reflected XSS via SQLConverterServlet | reliance | 5.1 (v4.0) | Medium |
| CVE-2025-71404 | better-auth before 1.1.16 Reflected XSS via error parameter | better-auth | 5.1 (v4.0) | Medium |
| CVE-2026-19434 | Stored Cross-site Scripting in Pentestify finding severity field | Pentestify | 5.1 (v4.0) | Medium |
| CVE-2026-19716 | Stored Cross-site Scripting in Pentestify user account deletion via unescaped username | Pentestify | 5.1 (v4.0) | Medium |
| CVE-2026-22675 | OCS Inventory NG Server Stored XSS via User-Agent | ocs inventory server | 5.1 (v4.0) | Medium |
| CVE-2026-25557 | Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter | PHP Directory Listing Script | 5.1 (v4.0) | Medium |
| CVE-2026-27176 | MajorDoMo - Cross-Site Scripting | majordomo | 5.1 (v4.0) | Medium |
| CVE-2026-32856 | Ellucian Banner Self-Service Reflected XSS via dateConverter | Banner Self-Service | 5.1 (v4.0) | Medium |
| CVE-2026-34416 | OSCAL-GUI Reflected XSS via project parameter in oscal.php | OSCAL-GUI | 5.1 (v4.0) | Medium |
| CVE-2026-34417 | OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php | OSCAL-GUI | 5.1 (v4.0) | Medium |
| CVE-2026-34798 | Endian Firewall /cgi-bin/routing.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34799 | Endian Firewall /manage/dnsmasq/hosts/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34800 | Endian Firewall /cgi-bin/uplinkeditor.cgi NAME Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34801 | Endian Firewall /manage/dhcp/fixed_leases/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34802 | Endian Firewall /cgi-bin/salearn.cgi remark user ham spam Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34803 | Endian Firewall /manage/qos/classes/ name Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34804 | Endian Firewall /manage/qos/rules/ dscp Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34805 | Endian Firewall /cgi-bin/dnat.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34806 | Endian Firewall /cgi-bin/snat.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34807 | Endian Firewall /cgi-bin/incoming.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34808 | Endian Firewall /cgi-bin/outgoingfw.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34809 | Endian Firewall /cgi-bin/zonefw.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34810 | Endian Firewall /cgi-bin/vpnfw.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34811 | Endian Firewall /cgi-bin/xtaccess.cgi remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34812 | Endian Firewall /cgi-bin/proxypolicy.cgi mimetypes Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34813 | Endian Firewall /cgi-bin/proxyuser.cgi user Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34814 | Endian Firewall /cgi-bin/proxygroup.cgi group Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34815 | Endian Firewall /cgi-bin/smtpdomains.cgi DOMAIN Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34816 | Endian Firewall /manage/smtpscan/domainrouting/ domain Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34817 | Endian Firewall /cgi-bin/smtprouting.cgi ADDRESS BCC Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34818 | Endian Firewall /manage/dnsmasq/localdomains/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34819 | Endian Firewall /cgi-bin/openvpnclient.cgi REMARK Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34820 | Endian Firewall /manage/ipsec/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34821 | Endian Firewall /manage/vpnauthentication/user/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34822 | Endian Firewall /manage/ca/certificate/ new_cert_name Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-34823 | Endian Firewall /manage/password/web/ remark Stored Cross-Site Scripting | firewall community | 5.1 (v4.0) | Medium |
| CVE-2026-35007 | Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35008 | Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35009 | Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35010 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35011 | Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35012 | Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35014 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35015 | Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-35016 | Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter | tickets | 5.1 (v4.0) | Medium |
| CVE-2026-40507 | OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal | openemr | 5.1 (v4.0) | Medium |
| CVE-2026-40508 | OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler | openemr | 5.1 (v4.0) | Medium |
| CVE-2026-4093 | Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels) | taxonomy term reference tree widget | 5.1 (v4.0) | Medium |
| CVE-2026-42840 | ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals | ERPNext | 5.1 (v4.0) | Medium |
| CVE-2026-45551 | Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write | groupoffice | 5.1 (v4.0) | Medium |
| CVE-2026-47106 | Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API | Banner Self-Service | 5.1 (v4.0) | Medium |
| CVE-2026-48214 | Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48215 | Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48218 | Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48219 | Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48220 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48221 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48222 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48223 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48224 | Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48225 | Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48226 | Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig Parameters | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48227 | Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48228 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48229 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter | Tickets | 5.1 (v4.0) | Medium |
| CVE-2026-48530 | GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48531 | GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48532 | GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48534 | GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48535 | GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48536 | GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48537 | GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48538 | GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48539 | GFI Archiver < 15.13 Stored XSS via MailInsights.aspx | GFI Archiver | 5.1 (v4.0) | Medium |
| CVE-2026-48559 | Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags | lms | 5.1 (v4.0) | Medium |
| CVE-2026-49131 | OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field | OPNsense | 5.1 (v4.0) | Medium |
| CVE-2026-49132 | OPNsense < 26.1.9 Stored XSS via Certificate Description Field | OPNsense | 5.1 (v4.0) | Medium |
| CVE-2026-53992 | Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters | ProjectSend | 5.1 (v4.0) | Medium |
| CVE-2026-56126 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php | pfSense Plus | 5.1 (v4.0) | Medium |
| CVE-2026-56127 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php | pfSense Plus | 5.1 (v4.0) | Medium |
| CVE-2026-56128 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php | pfSense Plus | 5.1 (v4.0) | Medium |
| CVE-2026-57857 | Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter | Flow Payment | 5.1 (v4.0) | Medium |
| CVE-2026-64628 | Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers | grav | 5.1 (v4.0) | Medium |
| CVE-2026-65697 | Fathom Lite 1.3.1 Stored XSS via /collect Endpoint | fathom | 5.1 (v4.0) | Medium |
| CVE-2026-66296 | Reflected XSS in oaskit's default HTML error handler | oaskit | 5.1 (v4.0) | Medium |
| CVE-2026-67333 | better-auth before 1.6.13 Stored XSS via javascript redirect_uri | better-auth | 5.1 (v4.0) | Medium |
| CVE-2026-68583 | luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name | luci | 5.1 (v4.0) | Medium |
| CVE-2026-71503 | Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template | dolibarr | 5.1 (v4.0) | Medium |
| CVE-2026-72743 | SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html | SQLBot | 5.1 (v4.0) | Medium |
| CVE-2026-72747 | AVideo Stored Cross-Site Scripting via Unauthenticated Registration | AVideo | 5.1 (v4.0) | Medium |
| CVE-2026-72821 | Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle | grav | 5.1 (v4.0) | Medium |
| CVE-2026-72832 | Grav before 2.0.12 Stored XSS via quoted-attribute bypass | grav | 5.1 (v4.0) | Medium |
| CVE-2026-73319 | XenForo < 2.3.13 XSS via Dynamic Redirect Handler | xenforo | 5.1 (v4.0) | Medium |
| CVE-2026-75831 | Grav before 2.0.15 Stored XSS via audio/video source URL | grav | 5.1 (v4.0) | Medium |
| CVE-2026-84477 | AVideo Stored XSS via Live Schedule Title Description | AVideo | 5.1 (v4.0) | Medium |
| CVE-2026-85593 | phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode | phpMyFAQ | 5.1 (v4.0) | Medium |
| CVE-2026-85600 | Grav Admin before 2.0.21 Stored XSS via username | grav-plugin-admin2 | 5.1 (v4.0) | Medium |
| CVE-2026-86197 | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox | grav | 5.1 (v4.0) | Medium |
| CVE-2013-6043 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 5.0 (v2.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2017-14651 | WSO2 Data Analytics Server 3.1.0 - Cross-Site Scripting | api manager | 4.8 (v3.1) | Medium |
| CVE-2018-1186 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1187 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1188 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1189 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1201 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1202 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2020-29240 | LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting | leptoncms | 4.8 (v3.1) | Medium |
| CVE-2024-3822 | Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS | base64 encoderdecoder | 4.8 (v3.1) | Medium |
| CVE-2025-15669 | Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label | Bit Form | 4.8 (v3.1) | Medium |
| CVE-2026-26211 | Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field | Ekushey Project Manager CRM | 4.8 (v4.0) | Medium |
| CVE-2026-34246 | CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output | panel | 4.8 (v3.1) | Medium |
| CVE-2026-39390 | CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting | ci4ms | 4.8 (v3.1) | Medium |
| CVE-2026-39392 | CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization | ci4ms | 4.8 (v3.1) | Medium |
| CVE-2026-65930 | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields | LimeSurvey | 4.8 (v4.0) | Medium |
| CVE-2026-67612 | OpenEMR 8.2.0 Stored XSS via import_template.php Template Management | openemr | 4.8 (v4.0) | Medium |
| CVE-2026-67617 | Microweber CMS 2.0.20 Stored XSS via tag_names Parameter | microweber | 4.8 (v4.0) | Medium |
| CVE-2026-70560 | Ultimate POS Stored XSS via First Name Field in Leave Notifications | Ultimate POS (Stock Management & Point of Sale) | 4.8 (v4.0) | Medium |
| CVE-2026-79663 | Ech0 before 4.7.3 Stored XSS via RSS feed tag names | Ech0 | 4.8 (v4.0) | Medium |
| CVE-2026-79670 | Ech0 before 4.4.3 Stored XSS via SVG Upload | Ech0 | 4.8 (v4.0) | Medium |
| CVE-2026-84188 | librenms before 26.7.0 Stored XSS via graph_descr settings | librenms | 4.8 (v4.0) | Medium |
| CVE-2026-3093 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | gitlab | 4.7 (v3.1) | Medium |
| CVE-2026-16273 | Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta | Narrative Publisher | 4.6 (v3.1) | Medium |
| CVE-2026-53468 | Typemill has Stored HTML Attribute Injection in Metadata Fields | typemill | 4.6 (v3.1) | Medium |
| CVE-2026-75331 | tamguo 1.5.3 Cross-Site Scripting Vulnerability | - | 4.6 (v3.1) | Medium |
| CVE-2008-2398 | AppServ Open Project <=2.5.10 - Cross-Site Scripting | appserv | 4.3 (v2.0) | Medium |
| CVE-2008-6465 | Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting | h-sphere | 4.3 (v2.0) | Medium |
| CVE-2013-6042 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 4.3 (v2.0) | Medium |
| CVE-2014-100004 | Sitecore CMS - Cross-Site Scripting | sitecore.net | 4.3 (v2.0) | Medium |
| CVE-2014-3110 | Honeywell XL Web Controller - Cross-Site Scripting | falcon xlweb linux controller | 4.3 (v2.0) | Medium |
| CVE-2015-1389 | Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting | clearpass policy manager | 4.3 (v2.0) | Medium |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 (v2.0) | Medium |
| CVE-2015-6402 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 4.3 (v2.0) | Medium |
| CVE-2018-6225 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 4.3 (v3.0) | Medium |
| CVE-2020-7318 | McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scripting | epolicy orchestrator | 4.3 (v3.1) | Medium |
| CVE-2024-34061 | Changedetection.io <=v0.45.21 - Cross-Site Scripting | changedetection.io | 4.3 (v3.1) | Medium |
| CVE-2026-12724 | Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password | Kirki | 4.3 (v3.1) | Medium |
| CVE-2026-32250 | NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/ | Nameless | 4.3 (v3.1) | Medium |
| CVE-2026-55566 | Yamcs: DOM XSS in Extension Routing | yamcs | 4.3 (v3.1) | Medium |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection | Nexter Blocks | 3.8 (v3.1) | Low |
| CVE-2026-10827 | Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes | Spectra Legacy | 3.5 (v3.1) | Low |
| CVE-2026-13393 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) | ElementsKit Elementor Addons | 3.5 (v3.1) | Low |
| CVE-2026-66300 | SNOMED International Snowstorm reflected XSS | Snowstorm | 2.3 (v4.0) | Low |
| CVE-2026-10153 | westboy CicadasCMS AbstractCacheManager.java search cross site scripting | CicadasCMS | 2.1 (v4.0) | Low |
| CVE-2026-10173 | Orthanc Explorer 2 URL StudyList.vue cross site scripting | Explorer 2 | 2.1 (v4.0) | Low |
| CVE-2026-10289 | code-projects Hotel and Tourism Reservation System tour.php cross site scripting | Hotel and Tourism Reservation System | 2.1 (v4.0) | Low |
| CVE-2026-10301 | itsourcecode Fees Management System index.php cross site scripting | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10810 | itsourcecode Fees Management System navbar.php cross site scripting | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-11436 | Mage AI Sign-in Flow index.tsx useMutation cross site scripting | Mage AI | 2.1 (v4.0) | Low |
| CVE-2026-11512 | itsourcecode Hospital Management System billing.php cross site scripting | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-11518 | SourceCodester Inventory System User Management users.php cross site scripting | Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-16220 | code-projects Online Examination System account.php cross site scripting | Online Examination System | 2.1 (v4.0) | Low |
| CVE-2026-16229 | itsourcecode Courier Management System index.php cross site scripting | Courier Management System | 2.1 (v4.0) | Low |
| CVE-2026-16485 | SourceCodester Class and Exam Timetabling System class.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-16486 | SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-18968 | ttttonyhe OBlog tags.php cross site scripting | OBlog | 2.1 (v4.0) | Low |
| CVE-2026-19378 | code-projects Task Management System CommentSave.php cross site scripting | Task Management System | 2.1 (v4.0) | Low |
| CVE-2026-19998 | code-projects Online Shopping System offersmail.php cross site scripting | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-5825 | code-projects Simple Laundry System delmemberinfo.php cross site scripting | Simple Laundry System | 2.1 (v4.0) | Low |
| CVE-2026-5826 | code-projects Simple IT Discussion Forum edit-category.php cross site scripting | Simple IT Discussion Forum | 2.1 (v4.0) | Low |
| CVE-2026-59727 | Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands | astro | 2.1 (v4.0) | Low |
| CVE-2026-66882 | Reflected XSS in AshAuthentication confirmation and magic link interaction forms | ash authentication | 2.1 (v4.0) | Low |
| CVE-2026-75077 | SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-75078 | SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-78054 | SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-78055 | SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting | Class and Exam Timetabling System | 2.1 (v4.0) | Low |
| CVE-2026-78059 | SourceCodester Stock Management System printOrder.php cross site scripting | Stock Management System | 2.1 (v4.0) | Low |
| CVE-2026-78060 | SourceCodester Stock Management System getOrderReport.php cross site scripting | Stock Management System | 2.1 (v4.0) | Low |
| CVE-2026-79793 | code-projects Online Shopping System sumit_form.php cross site scripting | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-82601 | SeaCMS err.php cross site scripting | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82625 | code-projects Simple Inventory System User Registration register.php cross site scripting | Simple Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82664 | yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting | GEOFlow | 2.1 (v4.0) | Low |
| CVE-2026-82700 | code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-85021 | langgenius dify Splash Layout splash.tsx router.replace cross site scripting | dify | 2.1 (v4.0) | Low |
| CVE-2026-85382 | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting | cms | 2.1 (v4.0) | Low |
| CVE-2026-86216 | code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting | Hotel and Tourism Reservation in PHP | 2.1 (v4.0) | Low |
| CVE-2026-86244 | FastAdmin User Controller User.php login cross site scripting | FastAdmin | 2.1 (v4.0) | Low |
| CVE-2026-86278 | SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting | Syllabus-Aligned Learning Management & Examination System | 2.1 (v4.0) | Low |
| CVE-2026-86294 | SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting | Simple Traffic Offense System | 2.1 (v4.0) | Low |
| CVE-2026-86668 | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting | iWebShop-5 | 2.1 (v4.0) | Low |
| CVE-2026-87926 | Rizwan17 inventory-management-system Login Page index.php cross site scripting | inventory-management-system | 2.1 (v4.0) | Low |
| CVE-2026-9415 | code-projects Employee Management System eloginwel.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9416 | code-projects Employee Management System myprofile.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9417 | code-projects Employee Management System myprofileup.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9418 | code-projects Employee Management System changepassemp.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9419 | code-projects Employee Management System empproject.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9448 | code-projects Employee Management System applyleave.php cross site scripting | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9518 | hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting | CodeIgniter-StudentManagementSystem | 2.1 (v4.0) | Low |
| CVE-2026-9519 | stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting | pingvin-share | 2.1 (v4.0) | Low |
| CVE-2026-9520 | blitz-js blitz Sign-in LoginForm.tsx cross site scripting | blitz | 2.1 (v4.0) | Low |
| CVE-2026-9527 | itsourcecode Electronic Judging System judges.php cross site scripting | Electronic Judging System | 2.1 (v4.0) | Low |
| CVE-2026-9566 | teableio teable Sign-up LoginPage.tsx cross site scripting | teable | 2.1 (v4.0) | Low |
| CVE-2026-10228 | raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting | student management system by php | 2.0 (v4.0) | Low |
| CVE-2026-10234 | Mettle sendportal Campaign webview cross site scripting | sendportal | 2.0 (v4.0) | Low |
| CVE-2026-10244 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting | Pharmacy Sales and Inventory System | 2.0 (v4.0) | Low |
| CVE-2026-10245 | SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting | Pharmacy Sales and Inventory System | 2.0 (v4.0) | Low |
| CVE-2026-10246 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting | Pharmacy Sales and Inventory System | 2.0 (v4.0) | Low |
| CVE-2026-10247 | SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting | Pharmacy Sales and Inventory System | 2.0 (v4.0) | Low |
| CVE-2026-10567 | 1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting | CordysCRM | 2.0 (v4.0) | Low |
| CVE-2026-16155 | SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting | Class and Exam Timetabling System | 2.0 (v4.0) | Low |
| CVE-2026-16156 | SourceCodester Class and Exam Timetabling System forexam.php cross site scripting | Class and Exam Timetabling System | 2.0 (v4.0) | Low |
| CVE-2026-16202 | SourceCodester Class and Exam Timetabling System CYS.php cross site scripting | Class and Exam Timetabling System | 2.0 (v4.0) | Low |
| CVE-2026-16203 | SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting | Class and Exam Timetabling System | 2.0 (v4.0) | Low |
| CVE-2026-19209 | SourceCodester Photo Share Website index.php home cross site scripting | Photo Share Website | 2.0 (v4.0) | Low |
| CVE-2026-19922 | code-projects Online Shopping System checkout.php cross site scripting | Online Shopping System | 2.0 (v4.0) | Low |
| CVE-2026-5806 | code-projects Easy Blog Site update.php cross site scripting | Easy Blog Site | 2.0 (v4.0) | Low |
| CVE-2026-5810 | SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting | Sales and Inventory System | 2.0 (v4.0) | Low |
| CVE-2026-7222 | code-projects Coaching Management System Complaint Form complaint.php cross site scripting | Coaching Management System | 2.0 (v4.0) | Low |
| CVE-2026-8139 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName | concrete cms | 2.0 (v4.0) | Low |
| CVE-2026-82483 | coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting | Coppermine Photo Gallery | 2.0 (v4.0) | Low |
| CVE-2026-82488 | Beetel 450TC3 User Management cross site scripting | 450TC3 | 2.0 (v4.0) | Low |
| CVE-2026-82622 | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting | Employee Leave Managing System | 2.0 (v4.0) | Low |
| CVE-2026-82665 | yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal | GEOFlow | 2.0 (v4.0) | Low |
| CVE-2026-82666 | yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection | GEOFlow | 2.0 (v4.0) | Low |
| CVE-2026-82667 | yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forger | GEOFlow | 2.0 (v4.0) | Low |
| CVE-2026-84437 | OpenCart Autocomplete Workflow address.php cross site scripting | OpenCart | 2.0 (v4.0) | Low |
| CVE-2026-84438 | OpenCart Autocomplete Workflow edit.php cross site scripting | OpenCart | 2.0 (v4.0) | Low |
| CVE-2026-85022 | langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting | dify | 2.0 (v4.0) | Low |
| CVE-2026-85207 | itsourcecode Online Medicine Delivery System index.php cross site scripting | Online Medicine Delivery System | 2.0 (v4.0) | Low |
| CVE-2026-86181 | code-projects Task Management System User Profile Update UpdateUserProfile.php cross site scripting | Task Management System | 2.0 (v4.0) | Low |
| CVE-2026-86301 | code-projects Hospital Information System Patient Management editPatient.php cross site scripting | Hospital Information System | 2.0 (v4.0) | Low |
| CVE-2026-86644 | star7th showdoc API Page Save Endpoint editormd.js cross site scripting | showdoc | 2.0 (v4.0) | Low |
| CVE-2026-10112 | sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting | STUDENT-MANAGEMENT-SYSTEM | 1.9 (v4.0) | Low |
| CVE-2026-10529 | westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting | CicadasCMS | 1.9 (v4.0) | Low |
| CVE-2026-11434 | FluentCMS Blocks Plugin blocks cross site scripting | FluentCMS | 1.9 (v4.0) | Low |
| CVE-2026-11468 | SourceCodester Hospitals Patient Records Management System page room_types cross site scripting | Hospitals Patient Records Management System | 1.9 (v4.0) | Low |
| CVE-2026-16205 | Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting | CMS | 1.9 (v4.0) | Low |
| CVE-2026-19110 | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting | DataGear | 1.9 (v4.0) | Low |
| CVE-2026-19207 | PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting | Company Visitor Management System | 1.9 (v4.0) | Low |
| CVE-2026-5834 | code-projects Online Shoe Store admin_running.php cross site scripting | Online Shoe Store | 1.9 (v4.0) | Low |
| CVE-2026-5835 | code-projects Online Shoe Store admin_football.php cross site scripting | Online Shoe Store | 1.9 (v4.0) | Low |
| CVE-2026-5836 | code-projects Online Shoe Store admin_product.php cross site scripting | Online Shoe Store | 1.9 (v4.0) | Low |
| CVE-2026-9564 | SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting | Hospitals Patient Records Management System | 1.9 (v4.0) | Low |
| CVE-2026-78187 | Piwigo Public Authentication cross site scripting | Piwigo | 1.3 (v4.0) | Low |
| CVE-2022-38322 | Temenos Transact - Cross-Site Scripting | - | N/A | N/A |
| CVE-2026-78849 | Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 Arbitrary Code Execution Vulnerability | Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 | N/A | N/A |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.