Security Risk Category

Cross-site Scripting Security Risks — Page 8

Published vulnerability pages connected to Cross-site Scripting. Each page keeps one canonical URL and focused remediation guidance.

260 published Cross-site Scripting risks

Cross-site Scripting risks

Showing 253–260 of 260 published risks.

mediumEPSS 0.002

Bookero.pl WordPress Plugin Stored Cross-Site Scripting Vulnerability

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.

CVE-2026-6910wordpressxss

Updated Jul 10, 2026

criticalEPSS 0.004

ValeApp Stored Cross-Site Scripting Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-2342web-applicationxss

Updated Jul 10, 2026

mediumEPSS 0.003

BiEticaret Reflected Cross-Site Scripting Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.

CVE-2026-5793web-applicationxss

Updated Jul 10, 2026

high

EventPrime WordPress Plugin Stored Cross-Site Scripting Vulnerability

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the plugin's Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a subscriber-level authenticated account.

CVE-2026-13441wordpressxss

Updated Jul 10, 2026

high

WP Cost Estimation & Payment Forms Builder Stored XSS Vulnerability

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-9253wordpresswoocommercexss

Updated Jul 10, 2026

medium

OKRs & Goals Stored Cross-Site Scripting Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.

CVE-2026-5005web-applicationxss

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.018

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

CVE-2025-48700npmxssinformation-disclosure

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.056

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVE-2026-42897npmbrowsermicrosoftxss

Updated Jul 9, 2026