Security Risk Category
Web Application Security Risks — Page 3
Published vulnerability pages connected to Web Application. Each page keeps one canonical URL and focused remediation guidance.
239 published Web Application risks
Web Application risks
Showing 73–108 of 239 published risks.
CVE-2026-55019 in Microsoft SharePoint Server
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Updated Jul 15, 2026
CVE-2026-55020 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55021 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55030 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55034 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55135 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-56157 in Microsoft SharePoint Server
Microsoft SharePoint Server has an access control issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-58277 in Microsoft SharePoint Server
Microsoft SharePoint Server has an authorization issue that can let an authorized attacker gain higher privileges over the network.
Updated Jul 15, 2026
CVE-2026-45063 in Symfony Security HTTP
Symfony Security HTTP can spoof a certificate identity when X509Authenticator parses a crafted DN.
Updated Jul 15, 2026
CVE-2026-45064 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave visual-spoofing BiDi characters in sanitized URLs.
Updated Jul 15, 2026
CVE-2026-45069 in Symfony Security HTTP
Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.
Updated Jul 15, 2026
CVE-2026-45070 in Symfony MIME
Symfony MIME can allow email header injection through unsafe MIME parameter names.
Updated Jul 15, 2026
CVE-2026-45073 in Symfony Cache
Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.
Updated Jul 15, 2026
CVE-2026-45075 in Symfony Security HTTP
Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.
Updated Jul 15, 2026
CVE-2026-45133 in Symfony YAML
Symfony YAML can crash a worker when it parses very deeply nested YAML input.
Updated Jul 15, 2026
CVE-2026-45304 in Symfony YAML
Symfony YAML can use too much memory when crafted aliases expand recursively.
Updated Jul 15, 2026
CVE-2026-45305 in Symfony YAML
Symfony YAML can hang on crafted YAML because of slow regex backtracking.
Updated Jul 15, 2026
CVE-2026-45071 in Symfony DomCrawler
Symfony DomCrawler can read local files when it parses attacker-controlled XML content.
Updated Jul 15, 2026
CVE-2026-47212 in Symfony Twilio Notifier
Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.
Updated Jul 15, 2026
CVE-2026-47984 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47988 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47992 in Adobe Commerce
Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.
Updated Jul 15, 2026
CVE-2026-47994 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47995 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47996 in Adobe Commerce
Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47997 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47998 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47999 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48000 in Adobe Commerce
Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.
Updated Jul 15, 2026
CVE-2026-48001 in Adobe Commerce
Adobe Commerce can expose limited sensitive information under certain conditions.
Updated Jul 15, 2026
CVE-2026-48356 in Adobe Commerce
Adobe Commerce allows dangerous file upload in a way that can lead to code execution after user interaction.
Updated Jul 15, 2026
CVE-2026-48358 in Adobe Commerce
Adobe Commerce has an output escaping issue that can lead to code execution without user interaction.
Updated Jul 15, 2026
CVE-2026-48371 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48489 in Symfony Security HTTP
Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.
Updated Jul 15, 2026
CVE-2026-48747 in Symfony Mailomat Mailer
Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.
Updated Jul 15, 2026
CVE-2026-48760 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.
Updated Jul 15, 2026
