CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,769 vulnerabilities with CWE-79
CVE-2026-48320
HIGH
Adobe ColdFusion 2025 < 10 - XSS
CVSS 8.5
CVE-2026-48761
MEDIUM
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
CVSS 6.1
CVE-2026-48371
MEDIUM
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48355
MEDIUM
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48263
MEDIUM
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 5.4
CVE-2026-48262
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48261
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48260
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48257
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48255
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48254
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-48253
MEDIUM
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVSS 5.4
CVE-2026-47999
MEDIUM
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 4.8
CVE-2026-47995
HIGH
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 8.1
CVE-2026-47994
HIGH
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
CVSS 8.7
CVE-2026-47428
CRITICAL
Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
CVSS 9.6
CVE-2026-47423
HIGH
DOMPurify XSS via `selectedcontent` re-clone
CVSS 8.2
CVE-2026-45753
MEDIUM
Symfony HtmlSanitizer - Cross-Site Scripting via Unsanitized URL Attributes
CVSS 6.1
CVE-2026-45072
MEDIUM
Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
CVSS 5.4
CVE-2026-57101
HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-55135
MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55126
HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
CVE-2026-55034
HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
CVE-2026-55030
MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 4.6
CVE-2026-55021
HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 7.3
Details
Vulnerabilities
45,769
Exploit Likelihood
High