Security Risk Category

Cross-site Scripting Security Risks — Page 4

Published vulnerability pages connected to Cross-site Scripting. Each page keeps one canonical URL and focused remediation guidance.

260 published Cross-site Scripting risks

Cross-site Scripting risks

Showing 109–144 of 260 published risks.

high

RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time kses sanitization does not mitigate this issue because the crafted payload uses only kses-allowed tags and attributes (such as an &lt;a&gt; element with title and href), and the dangerous attribute-breaking HTML is synthesized entirely at render time by the plugin's own comment_text filter.

CVE-2026-13042wordpressxss

Updated Jul 16, 2026

medium

SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-15324wordpresswoocommercexss

Updated Jul 16, 2026

medium

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that is when the unescaped twitter_message value is evaluated inside the JavaScript template literal.

CVE-2026-14987wordpressxss

Updated Jul 16, 2026

medium

Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-15652wordpressxss

Updated Jul 16, 2026

medium

Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful execution of the injected script is limited to victims who have the referenced ticket ID present in their cart cookie, meaning the payload only fires for users who have previously added that ticket to their cart.

CVE-2026-13755wordpressxss

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-11390 News Kit Addons for Elementor Stored XSS Vulnerability

The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an attacker to intercept and modify the elementor_ajax AJAX save request in order to bypass the client-side SELECT control restrictions and submit arbitrary tag-name values.

CVE-2026-11390wordpressxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-7640 WP Customer Area Stored XSS Vulnerability

The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-7640wordpressxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-57963 Mozilla Thunderbird Chat HTML Injection Vulnerability

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.

CVE-2026-57963browserxssinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-58519 MediaWiki Cargo Extension XSS Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1.

CVE-2026-58519phpweb-applicationxss

Updated Jul 15, 2026

medium

CVE-2026-13323 Eclipse Open VSX HTML Rendering Supply Chain Vulnerability

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users.

CVE-2026-13323browsersupply-chainweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-53907 MyComplianceOffice Stored XSS Vulnerability

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can upload a crafted SVG file containing malicious JavaScript code that is executed when the logo is rendered or opened. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

CVE-2026-53907microsoftweb-applicationxssfile-upload

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58031 MediaWiki API Sandbox XSS Vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.

CVE-2026-58031phpapi-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-53962 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community...

CVE-2026-53962web-applicationxssfile-upload

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-53963 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator...

CVE-2026-53963web-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55424 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript...

CVE-2026-55424web-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8595 in Grafana OSS

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVE-2026-8595browserdevopsweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55466 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege...

CVE-2026-55466phpweb-applicationxssfile-upload

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55481 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS...

CVE-2026-55481phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-57213 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or...

CVE-2026-57213network-securityweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57214 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to...

CVE-2026-57214network-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58591 in Drupal Colorbox

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

CVE-2026-58591drupalxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-54433 in Roundcube Webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or...

CVE-2026-54433web-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55016 in Microsoft SharePoint Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55016windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55019 in Microsoft SharePoint Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55019windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55020 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55020windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-55021 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55021windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55030 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55030windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-55034 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55034windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55135 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55135windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.009

CVE-2026-47994 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47994phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-47995 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47995phpbrowserweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.115

CVE-2026-47999 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.

CVE-2026-47999phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-48371 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.

CVE-2026-48371phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48761 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.

CVE-2026-48761phpweb-applicationinput-validationxss

Updated Jul 15, 2026

highEPSS 0.002

Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting

Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57718wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57711wordpressbrowserxss

Updated Jul 15, 2026