Skip to main content

CWE archive

CWE-79 CVEs

Programmatic archive

45,721 CVEs tagged with CWE-79565 Critical, 4,869 High, 37,172 Medium, 3,077 Low, 38 Unrated.

CVE-2026-66490

Published Jul 29, 2026

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

CVSS N/A · Unrated
evidence mentions
2

CVE-2026-65946

Published Jul 29, 2026

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS N/A · Unrated
evidence mentions
1

CVE-2026-8791

Published Jul 29, 2026

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to…

CVSS 6.4 · Medium
evidence mentions
11
Buzz score
31.4

CVE-2026-7436

Published Jul 29, 2026

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all ver…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-16655

Published Jul 29, 2026

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested…

CVSS 7.2 · High
evidence mentions
15
Buzz score
34.2

CVE-2026-16597

Published Jul 29, 2026

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to…

CVSS 7.2 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-13425

Published Jul 29, 2026

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient…

CVSS 7.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-18197

Published Jul 29, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Libr…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13605

Published Jul 29, 2026

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. B…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17162

Published Jul 29, 2026

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-17161

Published Jul 29, 2026

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versi…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15735

Published Jul 29, 2026

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-12939

Published Jul 29, 2026

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes i…

CVSS 6.4 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-12938

Published Jul 29, 2026

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and includi…

CVSS 6.4 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-14515

Published Jul 28, 2026

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48060

Published Jul 28, 2026

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-18084

Published Jul 28, 2026

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue aff…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7775

Published Jul 28, 2026

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 throug…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-67174

Published Jul 28, 2026

Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHTMLElement function treated any…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-66921

Published Jul 28, 2026

Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolating it into both the data-node-name attribute and the bod…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66919

Published Jul 28, 2026

Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly int…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66918

Published Jul 28, 2026

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node,…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65882

Published Jul 28, 2026

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15393

Published Jul 28, 2026

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta…

CVSS 6.4 · Medium
evidence mentions
16
Buzz score
34.8

CVE-2026-15016

Published Jul 28, 2026

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field v…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 45,721 CVEsPage 1 of 1829