Security Risk Category

Cross-site Scripting Security Risks — Page 5

Published vulnerability pages connected to Cross-site Scripting. Each page keeps one canonical URL and focused remediation guidance.

260 published Cross-site Scripting risks

Cross-site Scripting risks

Showing 145–180 of 260 published risks.

medium

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57735wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57708wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting

Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57695wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57691wordpressbrowsernetwork-securityxss

Updated Jul 15, 2026

highEPSS 0.002

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting

NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57668wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57706wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting

FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57816wordpresswoocommercebrowserxss

Updated Jul 15, 2026

highEPSS 0.001

ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting

ICS Calendar has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-59516wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution <= 3.1.7 - Unauthenticated Stored Cross-Site Scripting

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57715wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting

WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57712wordpressbrowserxss

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45753 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss JavaScript URLs in some attributes, which can allow cross-site scripting in sanitized HTML.

CVE-2026-45753phpweb-applicationinput-validationxss

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58034 in MediaWiki CheckUser

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.

CVE-2026-58034phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58035 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.

CVE-2026-58035phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-58028 in MediaWiki and CentralAuth

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth. This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58028phpapi-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58030 in MediaWiki SyntaxHighlight_GeSHi

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeSHi. This vulnerability is associated with program files includes/SyntaxHighlight.Php. This issue affects SyntaxHighlight_GeSHi: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58030phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58032 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Api/index.Js. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58032phpapi-securityweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-58037 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Language/Language.Php, includes/Logging/BlockLogFormatter.Php, includes/Logging/LogFormatter.Php, includes/Logging/PatrolLogFormatter.Php, includes/Logging/RenameuserLogFormatter.Php, includes/Logging/TagLogFormatter.Php, includes/Specials/SpecialVersion.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58037phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.002

CVE-2026-58038 in MediaWiki Timeline

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files includes/Timeline.Php, scripts/EasyTimeline.Pl. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58038phpweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-57829 in Helix Ultimate for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

CVE-2026-57829joomlaxssauthentication-bypass

Updated Jul 15, 2026

medium

CVE-2026-58475 in Sustainable Irrigation Platform

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output encoding on rendered program names to execute arbitrary JavaScript in the browsers of any users viewing the affected page, with exploitation facilitated by the absence of a required passphrase or the default passphrase 'opendoor'.

CVE-2026-58475industrial-controlinput-validationxss

Updated Jul 15, 2026

medium

CVE-2026-23573 in FortiProxy and FortiOS

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.

CVE-2026-23573network-securityinput-validationxss

Updated Jul 15, 2026

medium

CVE-2026-14358 in MediaWiki Charts Extension

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Charts Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-14358phpweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-54263 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is present for all sites, even if they do not enable the dynamic image serve view. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54263pythonweb-applicationxss

Updated Jul 14, 2026

medium

CVE-2025-71385 Netdata Vulnerability

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and serves the response with Content-Type image/svg+xml. An attacker can craft a URL such as /api/v2/ilove.svg?love=<script>...</script>; when a victim navigates to it the injected script executes in the victim browser in the origin of the Netdata instance (reflected cross-site scripting). These endpoints are registered with HTTP_ACL_NOCHECK and anonymous access and, because bearer-token protection is disabled by default, are reachable without authentication on a default Netdata agent. The issue was resolved by removing the ilove endpoint.

CVE-2025-71385browserapi-securityweb-applicationxss

Updated Jul 14, 2026

medium

CVE-2026-13373 fireware vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

CVE-2026-13373network-securityxss

Updated Jul 14, 2026

medium

CVE-2026-13374 fireware vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

CVE-2026-13374network-securityxss

Updated Jul 14, 2026

medium

CVE-2026-13375 fireware vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

CVE-2026-13375network-securityxss

Updated Jul 14, 2026

medium

CVE-2026-13376 fireware vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

CVE-2026-13376network-securityxss

Updated Jul 14, 2026

medium

CVE-2026-13377 fireware vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

CVE-2026-13377network-securityxss

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57977 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57977browsermicrosoftxss

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-58298 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58298browsermicrosoftxss

Updated Jul 13, 2026

mediumEPSS 0.002

CVE-2026-58524 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58524browsermicrosoftxss

Updated Jul 13, 2026

medium

CVE-2025-8591 api control plane vulnerability

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

CVE-2025-8591browserapi-securityxss

Updated Jul 13, 2026

mediumEPSS 0.002

CVE-2026-50133 hugo vulnerability

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.

CVE-2026-50133xss

Updated Jul 13, 2026

mediumEPSS 0.002

CVE-2026-58402 hugo vulnerability

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.

CVE-2026-58402xss

Updated Jul 13, 2026

low

CVE-2026-0279 pan-os vulnerability

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.

CVE-2026-0279network-securityxss

Updated Jul 13, 2026