CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,769 vulnerabilities with CWE-79
CVE-2026-15652
MEDIUM
Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
CVSS 6.4
CVE-2026-14987
MEDIUM
GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
CVSS 6.4
CVE-2026-13005
MEDIUM
MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
CVSS 4.4
CVE-2026-54458
CRITICAL
AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
CVSS 9.6
CVE-2026-50183
MEDIUM
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
CVSS 4.7
CVE-2026-50182
MEDIUM
AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination
CVSS 6.1
CVE-2026-49279
HIGH
WWBN AVideo <= 29.0 MessageSQLite - Stored Cross-Site Scripting
CVE-2026-26719
MEDIUM
xxl-job-admin 3.0.0 - Remote Code Execution via Crafted HTTP GET Request with Malicious Script
CVSS 6.1
CVE-2026-49867
MEDIUM
DataEase: Authenticated Stored XSS in DataEase Template Static Resources
CVE-2026-45738
HIGH
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
CVSS 7.3
CVE-2026-62948
CRITICAL
OpenWrt < 25.12.5 odhcpd/LuCI - Stored Cross-Site Scripting
CVSS 9.6
CVE-2026-62378
CRITICAL
RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover
CVSS 9.0
CVE-2026-1563
MEDIUM
Pega Infinity < Infinity 25.1.2 - XSS
CVSS 4.8
CVE-2026-1562
MEDIUM
Pega Infinity < Infinity 25.1.2 - XSS
CVSS 4.8
CVE-2026-9007
MEDIUM
Reflected XSS in HCL Notes
CVE-2026-41580
MEDIUM
Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)
CVSS 6.1
CVE-2026-61453
MEDIUM
Grav before 2.0.1 XSS via Twig String Concatenation
CVSS 6.1
CVE-2026-58077
HIGH
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-57833
HIGH
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-47730
MEDIUM
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVSS 5.4
CVE-2026-46637
MEDIUM
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVSS 5.4
CVE-2026-42447
LOW
jadx: HTML Injection in Summary panel
CVSS 3.6
CVE-2026-49978
MEDIUM
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
CVSS 6.1
CVE-2026-49459
MEDIUM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVSS 6.1
CVE-2026-49458
MEDIUM
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
CVSS 6.1
Details
Vulnerabilities
45,769
Exploit Likelihood
High