<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Stored XSS</title>
  <link>https://cvedaily.com/pages/tags/stored-xss.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/stored-xss.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Stored XSS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-7299 – Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7299</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7299</strong></p>
  <p>Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28116 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28116</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28116</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS.  This issue affects Progress Planner: from n/a through 1.9.0.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24754 – Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24754</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24754</strong></p>
  <p>Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42676 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42676</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42676</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.  This issue affects myCred: from n/a through 3.0.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25599 – Missing authentication and clear‑text transmission of data from the heat pumps t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25599</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25599</strong></p>
  <p>Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an  unencrypted and unauthenticated HTTP connection on a non-secure po…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49384 – In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49384</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49384</strong></p>
  <p>In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-49381 – In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49381</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-49381</strong></p>
  <p>In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49368 – In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification tem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49368</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49368</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47694 – WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47694</guid>
    <pubDate>Fri, 29 May 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47694</strong></p>
  <p>WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when another user views the affected Gallery/category page. This is a stored XSS in the category descrip…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45551 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45551</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45551</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the email_font_size setting directly into JavaScript without escaping. By combining these two…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45343 – LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45343</guid>
    <pubDate>Thu, 28 May 2026 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45343</strong></p>
  <p>LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScript in an administrator's browser session. This affects instances configured with SSO/OAuth authentication, which is one of the supported authentication methods in LinkAce. An attacker who sets their OA…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47762 – TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47762</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47762</strong></p>
  <p>TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47761 – TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47761</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47761</strong></p>
  <p>TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47759 – TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47759</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47759</strong></p>
  <p>TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46426 – Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46426</guid>
    <pubDate>Wed, 27 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46426</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions are conditionally wrapped inside if (isPublicUser) or if (isPublicUser || !env.SELF_HOSTED), meaning any authenticated builder can upload executable web content — SVG fil…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49044 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49044</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49044</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS.  This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42759 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42759</guid>
    <pubDate>Wed, 27 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42759</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42751 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42751</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42751</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42750 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42750</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42750</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42738 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42738</guid>
    <pubDate>Wed, 27 May 2026 11:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42738</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42728 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42728</guid>
    <pubDate>Wed, 27 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42728</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27427 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27427</guid>
    <pubDate>Tue, 26 May 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27427</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS.  This issue affects Geo Mashup: from n/a through 1.13.18.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62745 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62745</guid>
    <pubDate>Mon, 25 May 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62745</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.  This issue affects Team Showcase: from n/a through 1.22.28.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48849 – In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48849</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48849</strong></p>
  <p>In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40607 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40607</guid>
    <pubDate>Fri, 22 May 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40607</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default, only users with Manager access level or above can save their filters publicly. This issue has been fix…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39970 – TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39970</guid>
    <pubDate>Fri, 22 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39970</strong></p>
  <p>TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restrict SVG/XML-based uploads and directly renders them when accessed through the domain. By uploading a crafted malicious SVG file containing embedded JavaScript, an attacker will execute arbitrary JavaSc…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8353 – Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8353</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8353</strong></p>
  <p>Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8139 – Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8139</guid>
    <pubDate>Thu, 21 May 2026 22:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8139</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.  Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4093 – In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4093</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4093</strong></p>
  <p>In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline.  Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/J…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8203 – Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8203</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8203</strong></p>
  <p>Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential theft, or other malicious actions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 s…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8197 – Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8197</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8197</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</strong> wrap is built by PHP string interpolation before t() runs, so the integration name lands in the translated output as raw HTML. A rogue admin co…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24573 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24573</guid>
    <pubDate>Wed, 20 May 2026 13:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24573</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS.  This issue affects Visualizer: from n/a before 4.0.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5776 – The Email Encoder  WordPress plugin before 2.4.7 does not escape email addresses...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5776</guid>
    <pubDate>Wed, 20 May 2026 07:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5776</strong></p>
  <p>The Email Encoder  WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34463 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34463</guid>
    <pubDate>Tue, 19 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34463</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current one, the clone form (bug_report_page.php) prepends the source Project name before the category selector without proper escaping, allowing an attacker able to to inject HTML if they can set the Project's…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7498 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7498</guid>
    <pubDate>Mon, 18 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7498</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS.  This issue affects DernekWeb: through 30122025.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44586 – SiYuan is an open-source personal knowledge management system. From 2.1.12 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44586</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44586</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42159 – Flowsint is an open-source OSINT graph exploration tool designed for cybersecuri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42159</guid>
    <pubDate>Thu, 14 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42159</strong></p>
  <p>Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites,…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42457 – vCluster Platform provides a Kubernetes platform for managing virtual clusters, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42457</guid>
    <pubDate>Thu, 14 May 2026 15:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42457</strong></p>
  <p>vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the platform's browser context. In the worst case, a malicious user could potentially c…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41932 – Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41932</guid>
    <pubDate>Thu, 14 May 2026 15:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41932</strong></p>
  <p>Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name field before sanitization occurs. Attackers can submit HTML and script markup in the username field during signup, which gets stripped from the username column but persisted verbatim in the display_name c…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42157 – Flowsint is an open-source OSINT graph exploration tool designed for cybersecuri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42157</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42157</strong></p>
  <p>Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malicious label that contains arbitrary HTML. When the map tab is selected and a map node marker is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixe…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41250 – Taiga is a project management platform for startups and agile developers. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41250</guid>
    <pubDate>Mon, 11 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41250</strong></p>
  <p>Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5784 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5784</guid>
    <pubDate>Thu, 07 May 2026 13:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5784</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.  This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8080 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8080</guid>
    <pubDate>Thu, 07 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8080</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS.       This issue affects MISP before 2.5.37.     A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The application accepted arbitrary values for the TemplateElementAttribute type and category fields without validati…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27421 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27421</guid>
    <pubDate>Thu, 07 May 2026 09:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27421</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.  This issue affects Royal Elementor Addons: from n/a before 1.7.1053.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5110 – The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5110</guid>
    <pubDate>Sat, 02 May 2026 06:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5110</strong></p>
  <p>The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_sta…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40201 – @diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40201</guid>
    <pubDate>Fri, 01 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40201</strong></p>
  <p>@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42643 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42643</guid>
    <pubDate>Wed, 29 Apr 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42643</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5306 – The Check &amp; Log Email  WordPress plugin before 2.0.13 does not properly handle e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5306</guid>
    <pubDate>Tue, 28 Apr 2026 07:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5306</strong></p>
  <p>The Check & Log Email  WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4313 – AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4313</guid>
    <pubDate>Fri, 24 Apr 2026 12:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4313</strong></p>
  <p>AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser. Critically, this may allow the attacker to obtain the administrator authentication token and perform arbitrary actions w…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28040 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28040</guid>
    <pubDate>Thu, 23 Apr 2026 12:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28040</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62110 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62110</guid>
    <pubDate>Thu, 23 Apr 2026 12:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62110</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 3.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40593 – ChurchCRM is an open-source church management system. In versions prior to 7.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40593</guid>
    <pubDate>Sat, 18 Apr 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40593</strong></p>
  <p>ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking characters and event handlers, which execute in the browser of any administrator who subsequently views th…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40483 – ChurchCRM is an open-source church management system. In versions prior to 7.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40483</guid>
    <pubDate>Sat, 18 Apr 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40483</strong></p>
  <p>ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permissions can inject HTML attribute-breaking characters and event handlers into the comment field, which are stored in the database and execute in…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40479 – Kimai is an open-source time tracking application. In versions 1.16.3 through 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40479</guid>
    <pubDate>Fri, 17 Apr 2026 23:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40479</strong></p>
  <p>Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and rendered through innerHTML, this incomplete escaping allows HTML attribute injection. An authentica…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40353 – wger is a free, open-source workout and fitness manager. In versions 2.5 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40353</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40353</strong></p>
  <p>wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django's |safe filter. An authenticated user can create an ingredient with a malicious license_author value…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40322 – SiYuan is an open-source personal knowledge management system. In versions 3.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40322</guid>
    <pubDate>Thu, 16 Apr 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40322</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered output. On desktop builds using Electron, windows are created with nodeIntegrat…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6370 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6370</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6370</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Ajax Cart for WooCommerce allows Stored XSS.This issue affects Mini Ajax Cart for WooCommerce: from n/a through 1.3.4.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15636 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15636</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15636</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through <= 3.5.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4914 – Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4914</guid>
    <pubDate>Tue, 14 Apr 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4914</strong></p>
  <p>Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39426 – MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39426</guid>
    <pubDate>Tue, 14 Apr 2026 02:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39426</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <iframe_render> tags from LLM responses or Application Prologue configurations, bypassing standard Markdown sanitization and XSS filtering. The unsanitized HTML content is passed to the IframeRender.vue…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39425 – MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39425</guid>
    <pubDate>Tue, 14 Apr 2026 02:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39425</strong></p>
  <p>MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated users to inject arbitrary HTML and JavaScript into the Application prologue (Opening Remarks) field by wrapping malicious payloads in <html_rander> tags. The backend fails to sanitize or encode HTML entities in the prologue field when ap…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23900 – Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23900</guid>
    <pubDate>Sat, 11 Apr 2026 14:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23900</strong></p>
  <p>Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3568 – The MStore API plugin for WordPress is vulnerable to  Insecure Direct Object Ref...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3568</guid>
    <pubDate>Thu, 09 Apr 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3568</strong></p>
  <p>The MStore API plugin for WordPress is vulnerable to  Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys. The function reads raw JSON from php://input (line 1012), decodes it (line 1013)…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5301 – Stored XSS in log viewer in CoolerControl/coolercontrol-ui &lt;4.0.0 allows unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5301</guid>
    <pubDate>Wed, 08 Apr 2026 13:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5301</strong></p>
  <p>Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39708 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39708</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39708</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uicore UiCore Elements uicore-elements allows Stored XSS.This issue affects UiCore Elements: from n/a through <= 1.3.14.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39703 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39703</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39703</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through <= 1.8.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39692 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39692</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39692</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Stored XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39646 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39646</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39646</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaflet-map allows Stored XSS.This issue affects Leaflet Map: from n/a through <= 3.4.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39638 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39638</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39638</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39636 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39636</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39636</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through <= 9.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39615 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39615</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39615</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39604 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39604</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39604</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39541 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39541</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39541</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39500 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39500</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39500</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39483 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39483</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39483</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39846 – SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39846</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39846</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextI…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39841 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39841</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39841</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39839 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39839</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39839</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39837 – Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39837</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39837</strong></p>
  <p>Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39336 – ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39336</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39336</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, Person editor defaults rendered into address fields, and external self-registration form defaults. This is primarily an admin-to-admin stored XSS path where writable configuration fields are abused. This vulnerability is fixed in 7.1.…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39335 – ChurchCRM is an open-source church management system. Prior to 7.1.1, there is S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39335</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39335</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily an admin-to-admin stored XSS path when writable entity fields are abused. This vulnerability is fixed in 7.1.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35575 – ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35575</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35575</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator views the page. This enables attackers to steal the administrator’s session cookies, potentially lea…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35608 – QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35608</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35608</strong></p>
  <p>QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application allows SVG files to be uploaded via the /api/file/upload-chunk endpoint. An attacker can upload a specially crafted SVG file containing a JavaScript payload. When any user views the file preview, the script executes in the context of the application…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35399 – WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35399</guid>
    <pubDate>Mon, 06 Apr 2026 21:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35399</strong></p>
  <p>WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through a backup filename. This could lead to unauthorized execution of malicious code in the victim's browser, compromising session data or executing actions on behalf of the user. This vulnerability is fixed in 3.6.9.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34897 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34897</guid>
    <pubDate>Mon, 06 Apr 2026 15:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34897</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27655 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27655</guid>
    <pubDate>Fri, 03 Apr 2026 13:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27655</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4108 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4108</guid>
    <pubDate>Fri, 03 Apr 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4108</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4107 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4107</guid>
    <pubDate>Fri, 03 Apr 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4107</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3880 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3880</guid>
    <pubDate>Fri, 03 Apr 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3880</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3879 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3879</guid>
    <pubDate>Fri, 03 Apr 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3879</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28703 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28703</guid>
    <pubDate>Fri, 03 Apr 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28703</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28756 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28756</guid>
    <pubDate>Fri, 03 Apr 2026 11:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28756</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28754 – Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28754</guid>
    <pubDate>Fri, 03 Apr 2026 11:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28754</strong></p>
  <p>Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34932 – hoppscotch is an open source API development ecosystem. Prior to version 2026.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34932</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34932</strong></p>
  <p>hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34848 – hoppscotch is an open source API development ecosystem. Prior to version 2026.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34848</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34848</strong></p>
  <p>hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34725 – DbGate is cross-platform database manager. From version 7.0.0 to before version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34725</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34725</strong></p>
  <p>DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in the Electron desktop app this can escalate to local code execution because Electron is configured with…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34606 – Frappe Learning Management System (LMS) is a learning system that helps users st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34606</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34606</strong></p>
  <p>Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34729 – phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34729</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34729</strong></p>
  <p>phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34571 – CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34571</guid>
    <pubDate>Wed, 01 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34571</strong></p>
  <p>CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, al…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34571">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
