Cross-Site Scripting Vulnerabilities

36 advisories classified as Cross-Site Scripting

36

Total CVEs

21

Critical

15

High

CVE-2026-40487

Apr 18, 2026

High (8.9)

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to th...

Read Advisory

CVE-2025-40899

Apr 15, 2026

High (8.9)

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges c...

Read Advisory

CVE-2026-27243

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerab...

Read Advisory

CVE-2026-27245

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerab...

Read Advisory

CVE-2026-27246

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execu...

Read Advisory

CVE-2026-1116

Apr 12, 2026

High (8.2)

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of...

Read Advisory

CVE-2026-31845

Apr 11, 2026

Critical (9.3)

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects...

Read Advisory

CVE-2026-1115

Apr 10, 2026

Critical (9.6)

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` fu...

Read Advisory

CVE-2026-5301

Apr 8, 2026

High (7.6)

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries...

Read Advisory

CVE-2018-25248

Apr 4, 2026

High (7.2)

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a ne...

Read Advisory

CVE-2026-34563

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34559

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34566

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34567

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34569

Apr 1, 2026

Critical (9.9)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34571

Apr 1, 2026

Critical (9.9)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (...

Read Advisory

CVE-2026-34448

Mar 31, 2026

Critical (9.0)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gall...

Read Advisory

CVE-2026-34557

Mar 30, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34558

Mar 30, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-33506

Mar 26, 2026

High (8.8)

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability ...

Read Advisory

CVE-2026-32890

Mar 20, 2026

Critical (9.6)

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnera...

Read Advisory

CVE-2026-32940

Mar 20, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses d...

Read Advisory

CVE-2026-33135

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbit...

Read Advisory

CVE-2026-33136

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inj...

Read Advisory

CVE-2026-33172

Mar 20, 2026

High (8.7)

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset uplo...

Read Advisory

CVE-2026-32754

Mar 19, 2026

Critical (9.3)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification...

Read Advisory

CVE-2026-29183

Mar 6, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when typ...

Read Advisory

CVE-2026-26266

Mar 3, 2026

Critical (9.3)

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client ve...

Read Advisory

CVE-2026-1216

Feb 17, 2026

High (7.2)

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization...

Read Advisory

CVE-2019-25379

Feb 16, 2026

High (7.2)

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attac...

Read Advisory

CVE-2019-25394

Feb 16, 2026

High (7.2)

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST para...

Read Advisory

CVE-2019-25395

Feb 16, 2026

High (7.2)

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the...

Read Advisory

CVE-2026-2101

Feb 16, 2026

High (8.7)

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary s...

Read Advisory

CVE-2026-26930

Feb 16, 2026

High (7.2)

SmarterTools SmarterMail before 9526 allows XSS via MAPI requests....

Read Advisory

CVE-2026-0753

Feb 14, 2026

High (7.2)

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input s...

Read Advisory

CVE-2026-1843

Feb 14, 2026

High (7.2)

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and outpu...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.