CWE-79
High likelihoodImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
45,771 vulnerabilities with CWE-79
CVE-2026-55481
MEDIUM
Snipe-IT: CSS Injection via `header_color` Setting
CVSS 4.8
CVE-2026-55466
HIGH
Snipe-IT: Stored XSS via inline-served attachment
CVSS 8.7
CVE-2026-54714
MEDIUM
Logto: XSS via unescaped RelayState in SAML auto-submit form
CVSS 6.1
CVE-2026-55464
MEDIUM
Snipe-IT: Stored XSS via Markdown custom field
CVSS 5.4
CVE-2026-56667
HIGH
ZITADEL: Stored XSS via Default URI Redirect in Login V2
CVSS 7.3
CVE-2026-55890
MEDIUM
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()
CVSS 4.8
CVE-2026-3251
MEDIUM
XSS in Webremium's Mezunum Satiyorum
CVSS 6.4
CVE-2026-8595
MEDIUM
Grafana OSS - Stored XSS in the Table Panel (TableNG)
CVSS 6.8
CVE-2026-61492
LOW
Jetbrains YouTrack < 2026.2.17394 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 3.5
CVE-2026-61456
MEDIUM
Grav before 1.0.3 Stored XSS via SVG Upload API
CVSS 4.6
CVE-2026-59795
HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 8.1
CVE-2026-59794
HIGH
Jetbrains TeamCity < 2026.1.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.3
CVE-2026-56354
MEDIUM
n8n - Cross-Site Scripting and Open Redirect in Form Node
CVSS 4.1
CVE-2026-29519
HIGH
Lucee CFML Server Reflected XSS via URL Path Parsing
CVSS 8.2
CVE-2026-41877
MEDIUM
Stored XSS in R-SOFT DMS
CVE-2026-13710
MEDIUM
Powerful Addons For Elementor, Widgets & Templates For WordPress < 3.2.6 - XSS
CVSS 6.4
CVE-2026-13247
MEDIUM
Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
CVSS 6.4
CVE-2026-9838
MEDIUM
ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
CVSS 6.1
CVE-2026-3907
MEDIUM
Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
CVSS 6.4
CVE-2026-12924
MEDIUM
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
CVSS 6.4
CVE-2026-12108
MEDIUM
Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
CVSS 4.4
CVE-2026-15301
MEDIUM
BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVSS 6.4
CVE-2026-15299
MEDIUM
Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget
CVSS 6.4
CVE-2026-15298
HIGH
TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
CVSS 7.2
CVE-2026-15297
MEDIUM
Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting
CVSS 6.1
Details
Vulnerabilities
45,771
Exploit Likelihood
High