CVE-2026-25900
Published May 26, 2026Lack of output escaping leads to a XSS vector in the feed modules.
- evidence mentions
- 1
- Buzz score
- 11.9
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
32 results · Sorted by Highest Buzz score first
Lack of output escaping leads to a XSS vector in the feed modules.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the content history component.
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
An improper access check allows unauthorized access to com_config webservice endpoints.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
An improper access check allows privilege escalation through the com_users batch task.
An improper access check allows privilege escalation through the com_users batch task.
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
Lack of input filtering leads to an XSS vector in the HTML filter code.
An improper access check allows privileged users to overwrite media files without editing permissions.
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.