Skip to main content

CWE archive

CWE-87 CVEs

Programmatic archive

55 CVEs tagged with CWE-876 Critical, 12 High, 36 Medium, 1 Low, 0 Unrated.

CVE-2026-54002

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(),…

CVSS 8.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-55661

Published Jul 1, 2026

Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text parsing and the default link/image renderers did not sanitize…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-55237

Published Jun 18, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scr…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46492

Published Jun 9, 2026

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown ren…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-25688

Published Jun 9, 2026

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in th…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45314

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the channel webhook create/update flow accepts arbitrary profile…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42458

Published May 15, 2026

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwa…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42235

Published May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40321

Published Apr 17, 2026

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-14732

Published Apr 8, 2026

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-22711

Published Apr 7, 2026

Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remed…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-35534

Published Apr 7, 2026

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() a…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33510

Published Apr 6, 2026

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application imprope…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34598

Published Apr 2, 2026

YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious attacker can inject JavaScript wi…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33506

Published Mar 26, 2026

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-52563

Published Mar 2, 2026

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page param…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-27120

Published Feb 20, 2026

Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters mat…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-65961

Published Nov 25, 2025

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed i…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48076

Published Nov 4, 2025

Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert an XSS payload. This issue…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62418

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to uploa…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62415

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to uploa…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62414

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8561

Published Oct 15, 2025

The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1.7 due to insufficient input…

CVSS 6.4 · Medium

CVE-2025-55291

Published Aug 18, 2025

Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag…

CVSS 7.1 · High

CVE-2025-54369

Published Jul 24, 2025

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response doc…

CVSS 9.3 · Critical
Showing 1-25 of 55 CVEsPage 1 of 3