Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,731 CVEs tagged with CWE-79565 Critical, 4,872 High, 37,181 Medium, 3,077 Low, 36 Unrated.

CVE-2026-18361

Published Jul 30, 2026

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18360

Published Jul 30, 2026

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16969

Published Jul 30, 2026

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59328

Published Jul 30, 2026

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14592

Published Jul 30, 2026

The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape tha…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14207

Published Jul 30, 2026

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-ed…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13344

Published Jul 30, 2026

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13330

Published Jul 30, 2026

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-11881

Published Jul 30, 2026

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-3093

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 4.7 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-66490

Published Jul 29, 2026

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65946

Published Jul 29, 2026

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8791

Published Jul 29, 2026

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to…

CVSS 6.4 · Medium
evidence mentions
11
Buzz score
31.4

CVE-2026-7436

Published Jul 29, 2026

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all ver…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-16655

Published Jul 29, 2026

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested…

CVSS 7.2 · High
evidence mentions
15
Buzz score
34.2

CVE-2026-16597

Published Jul 29, 2026

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to…

CVSS 7.2 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-13425

Published Jul 29, 2026

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient…

CVSS 7.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-18197

Published Jul 29, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Libr…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13605

Published Jul 29, 2026

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. B…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17162

Published Jul 29, 2026

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-17161

Published Jul 29, 2026

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versi…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15735

Published Jul 29, 2026

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-12939

Published Jul 29, 2026

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes i…

CVSS 6.4 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-12938

Published Jul 29, 2026

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and includi…

CVSS 6.4 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-14515

Published Jul 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 45,731 CVEsPage 1 of 1830