CWE-79

High likelihood

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

45,751 vulnerabilities with CWE-79
CVE-2026-15334 MEDIUM
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute
CVSS 6.4
CVE-2026-15333 MEDIUM
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute
CVSS 6.4
CVE-2026-6454 MEDIUM
Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute
CVSS 6.4
CVE-2026-15100 MEDIUM
Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute
CVSS 6.4
CVE-2026-15968 HIGH
Progress MOVEit Transfer - Stored Cross-Site Scripting
CVSS 7.1
CVE-2026-65763 MEDIUM
Phoca Maps for Joomla 1.0.0-6.0.9 - Reflected Cross-Site Scripting
CVE-2026-65762 MEDIUM
Phoca Guestbook for Joomla 1.0.0-6.1.0 - Reflected Cross-Site Scripting
CVE-2026-47743 HIGH
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
CVSS 8.7
CVE-2026-65697 MEDIUM
Fathom Lite 1.3.1 Stored XSS via /collect Endpoint
CVSS 6.1
CVE-2026-48539 MEDIUM
GFI Archiver < 15.13 Stored XSS via MailInsights.aspx
CVSS 5.4
CVE-2026-48538 MEDIUM
GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx
CVSS 5.4
CVE-2026-48537 MEDIUM
GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx
CVSS 5.4
CVE-2026-48536 MEDIUM
GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx
CVSS 5.4
CVE-2026-48535 MEDIUM
GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx
CVSS 5.4
CVE-2026-48534 MEDIUM
GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx
CVSS 5.4
CVE-2026-48532 MEDIUM
GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx
CVSS 5.4
CVE-2026-48531 MEDIUM
GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx
CVSS 5.4
CVE-2026-48530 MEDIUM
GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx
CVSS 5.4
CVE-2026-65914 MEDIUM
DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
CVSS 6.1
CVE-2026-65912 MEDIUM
DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR
CVSS 6.1
CVE-2026-65911 MEDIUM
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
CVSS 6.1
CVE-2026-65901 MEDIUM
DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
CVSS 6.1
CVE-2026-65900 MEDIUM
DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
CVSS 6.1
CVE-2026-65898 HIGH
DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig
CVSS 7.2
CVE-2026-65606 CRITICAL
SiYuan < 3.7.2 - XSS to Remote Code Execution via Protocol Handler
CVSS 9.6
Details
Vulnerabilities 45,751
Exploit Likelihood High