<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cross-site Scripting (XSS)</title>
  <link>https://cvedaily.com/pages/tags/xss.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/xss.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cross-site Scripting (XSS)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-37700 – Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37700</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-37700</strong></p>
  <p>Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-26378 – Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26378</guid>
    <pubDate>Wed, 03 Jun 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-26378</strong></p>
  <p>Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39107 – A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39107</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39107</strong></p>
  <p>A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser ses…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-36460 – Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36460</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-36460</strong></p>
  <p>Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20233 – A vulnerability in the web-based user interface of Cisco Webex Meetings could ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20233</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20233</strong></p>
  <p>A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.  This vulnerability existed because of insufficient validation of user input. Prior to this vulnerability being addres…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42321 – GLPI is a free asset and IT management software package. Starting in version 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42321</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42321</strong></p>
  <p>GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-36748 – RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36748</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-36748</strong></p>
  <p>RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31114 – backpack/crud provides Create, Read, Update &amp; Delete (CRUD) functions for Backpa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31114</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31114</strong></p>
  <p>backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phishing campaign, in order to trick users or admins into clicking a malicious link, which under very specif…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47324 – ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47324</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47324</strong></p>
  <p>ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other users’ browsers. Critically, when chained with CVE‑2025‑11661, which allows unauthenticated access to backend endpoin…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10729 – An HTML injection vulnerability in the notification email for "Slow Redirect" an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10729</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10729</strong></p>
  <p>An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.   This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.</p>
  <p><strong>CVSS:</strong> 1.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14773 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14773</guid>
    <pubDate>Wed, 03 Jun 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14773</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.  This issue affects T-MAC Plus: 4.0-24.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15654 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15654</guid>
    <pubDate>Wed, 03 Jun 2026 09:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15654</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS.  This issue affects Prague: from n/a through 2.2.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7421 – The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7421</guid>
    <pubDate>Wed, 03 Jun 2026 00:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7421</strong></p>
  <p>The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This ma…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42849 – authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42849</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42849</strong></p>
  <p>authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5385 – An unauthenticated user with write access to the knowledge base can store an XSS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5385</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5385</strong></p>
  <p>An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item.   This issue affects glpi: before 11.0.7.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34077 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34077</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34077</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33553 – Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33553</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33553</strong></p>
  <p>Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33245 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33245</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33245</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30586 – Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30586</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30586</strong></p>
  <p>Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33244 – React Router is a router for React. In versions 7.5.1 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33244</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33244</strong></p>
  <p>React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or D…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7299 – Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7299</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7299</strong></p>
  <p>Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32250 – NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32250</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32250</strong></p>
  <p>NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response without proper sanitization or output encoding. An attacker can craft a malicious URL containing Ja…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28116 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28116</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28116</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS.  This issue affects Progress Planner: from n/a through 1.9.0.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42685 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42685</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42685</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS.  This issue affects WP Job Portal: from n/a through 2.5.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5191 – The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5191</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5191</strong></p>
  <p>The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34907 – Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34907</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34907</strong></p>
  <p>Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. An attacker can craft a malicious URL with JavaScript embedded in the locale parameter and send it to a victim. When the victim opens the link, the injected script will be executed in their browser.   This issue affects Wirtualna Uczelnia versions up…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52759 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52759</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52759</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS.  This issue affects Accordion FAQ: from n/a through 2.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8885 – The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8885</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8885</strong></p>
  <p>The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout() function, which concatenates the attribute values directly into an HTML style att…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4081 – The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4081</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4081</strong></p>
  <p>The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color', and 'bgcolor' parameters. These attribute values are directly interpolated into HTML attribute context without bei…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4080 – The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4080</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4080</strong></p>
  <p>The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses sanitize_text_field() on shortcode attributes like 'itemid', 'product_name', 'product_des…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3620 – The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3620</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3620</strong></p>
  <p>The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user ac…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2425 – The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2425</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2425</strong></p>
  <p>The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into perfor…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2382 – The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2382</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2382</strong></p>
  <p>The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1451 – The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1451</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1451</strong></p>
  <p>The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a lin…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1450 – The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1450</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1450</strong></p>
  <p>The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5085 – The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5085</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5085</strong></p>
  <p>The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3722 – The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3722</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3722</strong></p>
  <p>The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbit…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10567 – A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10567</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10567</strong></p>
  <p>A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10510 – Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10510</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10510</strong></p>
  <p>Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10100 – The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10100</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10100</strong></p>
  <p>The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10529 – A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10529</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10529</strong></p>
  <p>A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJobController.java of the component Task Scheduling Management Module. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10514 – A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10514</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10514</strong></p>
  <p>A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 mitigates this issue. Th…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10301 – A vulnerability was detected in itsourcecode Fees Management System 1.0. The aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10301</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10301</strong></p>
  <p>A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24754 – Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24754</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24754</strong></p>
  <p>Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24752 – Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24752</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24752</strong></p>
  <p>Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24751 – Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24751</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24751</strong></p>
  <p>Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10289 – A security flaw has been discovered in code-projects Hotel and Tourism Reservati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10289</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10289</strong></p>
  <p>A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42678 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42678</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42678</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS.  This issue affects GiveWP: from n/a through 4.14.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42676 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42676</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42676</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.  This issue affects myCred: from n/a through 3.0.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48865 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48865</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48865</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS.  This issue affects LearnPress: from n/a through 4.3.6.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48839 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48839</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48839</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS.  This issue affects WP Statistics: from n/a through 14.16.6.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48559 – Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48559</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48559</strong></p>
  <p>Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42683 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42683</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42683</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS.  This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42681 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42681</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42681</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS.  This issue affects e2pdf: from n/a through 1.32.14.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25599 – Missing authentication and clear‑text transmission of data from the heat pumps t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25599</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25599</strong></p>
  <p>Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an  unencrypted and unauthenticated HTTP connection on a non-secure po…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10247 – A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10247</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10247</strong></p>
  <p>A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10246 – A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10246</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10246</strong></p>
  <p>A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10245 – A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10245</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10245</strong></p>
  <p>A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10244 – A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10244</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10244</strong></p>
  <p>A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9024 – A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9024</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9024</strong></p>
  <p>A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8474 – A vulnerability was discovered on Stormshield Network Security 





  *  4.3.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8474</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8474</strong></p>
  <p>A vulnerability was discovered on Stormshield Network Security         *  4.3.0 to 4.3.41,    *  4.8.0 to 4.8.15,    *  5.0.0 to 5.0.5         It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page beha…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42253 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42253</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42253</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.  The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servl…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40545 – SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40545</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40545</strong></p>
  <p>SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser.  This issue affects SOPlanning version 1.55 and below.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40544 – SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40544</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40544</strong></p>
  <p>SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the victim’s browser when a user clicks the Edit button for the malicious backup.  This issue affects SOP…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10234 – A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10234</guid>
    <pubDate>Mon, 01 Jun 2026 08:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10234</strong></p>
  <p>A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10228 – A vulnerability was found in raisulislamg4 student_management_system_by_php up t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10228</guid>
    <pubDate>Mon, 01 Jun 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10228</strong></p>
  <p>A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a roll…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48209 – An improper neutralization of user-controllable input in OTRS or ((OTRS)) Commun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48209</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48209</strong></p>
  <p>An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into manipulated request URLs, attackers can execute arbitrary script code in the context of an authenticat…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10173 – A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10173</guid>
    <pubDate>Sun, 31 May 2026 08:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10173</strong></p>
  <p>A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attac…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10153 – A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c355...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10153</guid>
    <pubDate>Sat, 30 May 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10153</strong></p>
  <p>A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release app…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10112 – A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10112</guid>
    <pubDate>Sat, 30 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10112</strong></p>
  <p>A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has no…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34127 – A stored
cross-site scripting (XSS) vulnerability has been identified in the web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34127</guid>
    <pubDate>Fri, 29 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34127</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device configuration, which may be stored and executed in the administrator’s browser whe…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49384 – In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49384</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49384</strong></p>
  <p>In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-49381 – In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49381</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-49381</strong></p>
  <p>In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49375 – In JetBrains TeamCity before 2026.1, 
2025.11.5 reflected XSS was possible on th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49375</guid>
    <pubDate>Fri, 29 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49375</strong></p>
  <p>In JetBrains TeamCity before 2026.1,  2025.11.5 reflected XSS was possible on the repository download page</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49371 – In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49371</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49371</strong></p>
  <p>In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49368 – In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification tem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49368</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49368</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6824 – A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6824</guid>
    <pubDate>Fri, 29 May 2026 18:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6824</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potenti…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45668 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45668</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45668</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName lab…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-36324 – SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36324</guid>
    <pubDate>Fri, 29 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-36324</strong></p>
  <p>SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-33386 – QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33386</guid>
    <pubDate>Fri, 29 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-33386</strong></p>
  <p>QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the plugin page, the malicious content is automatically fetched, rendered, and execu…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25384 – Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25384</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25384</strong></p>
  <p>Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can post comments containing JavaScript code through the rpc.php endpoint that executes in other users' browsers when viewing forum replies.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47694 – WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47694</guid>
    <pubDate>Fri, 29 May 2026 14:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47694</strong></p>
  <p>WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when another user views the affected Gallery/category page. This is a stored XSS in the category descrip…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45580 – WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45580</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45580</strong></p>
  <p>WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canStream user can persist a key containing " plus an event handler via plugin/Live/saveLive.php, and any visitor (logged in…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48527 – HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48527</guid>
    <pubDate>Fri, 29 May 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48527</strong></p>
  <p>HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45551 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45551</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45551</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the email_font_size setting directly into JavaScript without escaping. By combining these two…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9811 – A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9811</guid>
    <pubDate>Fri, 29 May 2026 12:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9811</strong></p>
  <p>A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious sc…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9809 – A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9809</guid>
    <pubDate>Fri, 29 May 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9809</strong></p>
  <p>A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. W…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10058 – ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10058</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10058</strong></p>
  <p>ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10057 – ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10057</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10057</strong></p>
  <p>ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9243 – The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9243</guid>
    <pubDate>Fri, 29 May 2026 08:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9243</strong></p>
  <p>The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is placed into an unquoted HTML attribute (dir=) allowing attribute injection despite…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11262 – The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11262</guid>
    <pubDate>Fri, 29 May 2026 08:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11262</strong></p>
  <p>The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9714 – The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9714</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9714</strong></p>
  <p>The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id' shortcode attribute directly into a dynamically constructed shortcode string with…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6275 – The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6275</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6275</strong></p>
  <p>The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta(…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14042 – The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14042</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14042</strong></p>
  <p>The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and including, 13.4.1. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'project_details' custom field. This makes it possible for authenticated attack…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7430 – The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7430</guid>
    <pubDate>Fri, 29 May 2026 04:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7430</strong></p>
  <p>The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php` embeds snippet content directly into JavaScript string literals without escapin…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45343 – LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45343</guid>
    <pubDate>Thu, 28 May 2026 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45343</strong></p>
  <p>LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScript in an administrator's browser session. This affects instances configured with SSO/OAuth authentication, which is one of the supported authentication methods in LinkAce. An attacker who sets their OA…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9646 – A reflected cross-site scripting issue exists in URL handling.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9646</guid>
    <pubDate>Thu, 28 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9646</strong></p>
  <p>A reflected cross-site scripting issue exists in URL handling.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47762 – TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47762</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47762</strong></p>
  <p>TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47761 – TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47761</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47761</strong></p>
  <p>TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47760 – TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47760</guid>
    <pubDate>Thu, 28 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47760</strong></p>
  <p>TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47760">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
