Security Risk Category

Browser Security Risks — Page 2

Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.

215 published Browser risks

Browser risks

Showing 37–72 of 215 published risks.

highEPSS 0.003

CVE-2026-15765 in Google Chrome

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-15765browsermemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15766 in Google Chrome

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15766browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15767 in Google Chrome

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

CVE-2026-15767browserwindowsremote-code-executionmemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15768 in Google Chrome

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15768browserauthorization-bypass

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15769 in Google Chrome

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15769browserlinuxinput-validationprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15770 in Google Chrome

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15770browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15771 in Google Chrome

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15771browserwindowsinput-validationinformation-disclosure

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-15772 in Google Chrome

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15772browsermemory-corruptionprivilege-escalation

Updated Jul 16, 2026

criticalEPSS 0.003

CVE-2026-15773 in Google Chrome

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15773browserwindowsmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-15774 in Google Chrome

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15774browsermemory-corruptionprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15775 in Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15775browserauthorization-bypass

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15776 in Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15776browserremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15777 in Google Chrome

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15777browserlinuxmemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15778 in Google Chrome

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15778browserinput-validationauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-47730 in Twig

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

CVE-2026-47730phpbrowserxss

Updated Jul 16, 2026

mediumEPSS 0.002

CVE-2026-57962 Mozilla Thunderbird LDAP Memory Exhaustion Vulnerability

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.

CVE-2026-57962browserinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-57963 Mozilla Thunderbird Chat HTML Injection Vulnerability

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.

CVE-2026-57963browserxssinformation-disclosure

Updated Jul 15, 2026

medium

CVE-2026-13323 Eclipse Open VSX HTML Rendering Supply Chain Vulnerability

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users.

CVE-2026-13323browsersupply-chainweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-58281 Microsoft Edge Chromium Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58281browsermicrosoftremote-code-executionunsafe-deserialization

Updated Jul 15, 2026

low

CVE-2026-0275 in Prisma Browser

A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS.

CVE-2026-0275browserprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8595 in Grafana OSS

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVE-2026-8595browserdevopsweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.009

CVE-2026-47994 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47994phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-47995 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47995phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.002

Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting

Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57718wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57711wordpressbrowserxss

Updated Jul 15, 2026

medium

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57735wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57708wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting

Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57695wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57691wordpressbrowsernetwork-securityxss

Updated Jul 15, 2026

highEPSS 0.002

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting

NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57668wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57706wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting

FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57816wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting

ICS Calendar has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-59516wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution <= 3.1.7 - Unauthenticated Stored Cross-Site Scripting

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57715wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting

WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57712wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58596 in Microsoft Edge Chromium

Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.

CVE-2026-58596browserlinuxwindowsmicrosoft

Updated Jul 15, 2026