Cross-Site Scripting

XSS vulnerabilities allowing script injection
59 CVEs tagged.

CVE-2025-8589 7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can inject malicious scripts into...

Feb 3, 2026
CVE-2026-1210 6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pages using the Happy...

Feb 3, 2026
CVE-2026-1447 5.4

The Mail Mint WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to 1.19.2, allowing unauthenticated attackers to ...

Feb 3, 2026
CVE-2026-0617 7.2

This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scripts into customer profile fie...

Feb 3, 2026
CVE-2026-1058 7.1

The Form Maker WordPress plugin has a stored XSS vulnerability in versions up to 1.15.35. Unauthenticated attackers can inject malicious JavaScript in...

Feb 3, 2026
CVE-2026-1065 7.2

The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript code due to weak file ex...

Feb 3, 2026
CVE-2025-14274 5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages via the Bor...

Feb 3, 2026
CVE-2025-67481 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's jQueryMsg JavaScript library that allows attackers to inject malicious scripts into ...

Feb 3, 2026
CVE-2025-67483 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's page preview JavaScript component. Attackers can inject malicious scripts...

Feb 3, 2026
CVE-2025-61656 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia VisualEditor's clipboard handling component. It allows attackers to inject ...

Feb 3, 2026
CVE-2025-61657 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's Vector skin that allows attackers to inject malicious scripts into web pa...

Feb 3, 2026
CVE-2025-67475 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's CommentFormatter/CommentParser.php that allows attackers to inject malici...

Feb 3, 2026
CVE-2025-67477 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's ApiSandboxLayout.js file that allows attackers to inject malicious scripts into web ...

Feb 3, 2026
CVE-2025-67479 N/A

This vulnerability in MediaWiki and its Cite extension allows attackers to inject malicious content through parser functions. It affects all MediaWiki...

Feb 3, 2026
CVE-2025-61651 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension. Attackers can inject malicious scripts in...

Feb 3, 2026
CVE-2025-61655 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's VisualEditor component. Attackers can inject malicious scripts...

Feb 3, 2026
CVE-2025-61645 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's CodexTablePager component that allows attackers to inject malicious scripts into web...

Feb 3, 2026
CVE-2025-61648 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension. It allows attackers to inject malicious s...

Feb 3, 2026
CVE-2025-61650 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension that allows attackers to inject malicious scripts int...

Feb 3, 2026
CVE-2025-11261 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's JavaScript language module that allows attackers to inject malicious scripts into we...

Feb 3, 2026
CVE-2025-61642 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's HTML form components that allows attackers to inject malicious scripts in...

Feb 3, 2026
CVE-2025-61644 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's WatchlistTopSectionWidget.js component. It allows attackers to inject mal...

Feb 3, 2026
CVE-2025-61636 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's HTMLButtonField.php that allows attackers to inject malicious scripts into web pages...

Feb 3, 2026
CVE-2025-61637 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's edit preview functionality. Attackers can inject malicious scripts that execute in u...

Feb 3, 2026
CVE-2025-61638 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki and Parsoid that allows attackers to inject malicious scripts into web pages. It affec...

Feb 3, 2026
CVE-2025-61640 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's RclToOrFromWidget.js component that allows attackers to inject malicious scripts int...

Feb 3, 2026
CVE-2026-25144 5.3

A stored cross-site scripting (XSS) vulnerability exists in Talishar's in-game chat system where the playerID parameter in SubmitChat.php is saved wit...

Feb 2, 2026
CVE-2026-24737 8.1

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user-controlled input to specific ...

Feb 2, 2026
CVE-2026-23476 5.4

This reflected XSS vulnerability in FacturaScripts allows attackers to inject malicious scripts into error messages that get executed in users' browse...

Feb 2, 2026
CVE-2026-23997 8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...

Feb 2, 2026
CVE-2025-6594 4.7

This XSS vulnerability in MediaWiki's ApiSandbox.js allows attackers to inject malicious scripts into web pages viewed by other users. It affects Medi...

Feb 2, 2026
CVE-2025-6595 4.7

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's MultimediaViewer component. Attackers can inject malicious scr...

Feb 2, 2026
CVE-2025-6596 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia's Vector skin that allows attackers to inject malicious scripts into web pages. It aff...

Feb 2, 2026
CVE-2025-70958 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in Subrion CMS v4.2.1 installation module allow attackers to inject malicious JavaScript...

Feb 2, 2026
CVE-2025-70959 5.4

A stored cross-site scripting vulnerability in Tendenci CMS allows attackers to inject malicious scripts into the Jobs module. When users view affecte...

Feb 2, 2026
CVE-2025-70960 5.4

A stored cross-site scripting (XSS) vulnerability in Tendenci CMS v15.3.7 allows attackers to inject malicious scripts into forum posts that execute w...

Feb 2, 2026
CVE-2026-20711 6.5

A cross-site scripting vulnerability in the email function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary user...

Feb 2, 2026
CVE-2026-22881 5.7

A cross-site scripting vulnerability in the Message function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary us...

Feb 2, 2026
CVE-2025-15396 7.1

The Library Viewer WordPress plugin before version 3.2.0 contains a reflected cross-site scripting (XSS) vulnerability where unsanitized parameters ar...

Feb 2, 2026
CVE-2026-25200 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading to stored cross-site scriptin...

Feb 2, 2026
CVE-2026-1744 2.4

This CVE describes a cross-site scripting (XSS) vulnerability in D-Link DSL-6641K routers running firmware version N8.TR069.20131126. Attackers can in...

Feb 2, 2026
CVE-2023-54343 6.4

QWE DL 2.0.1 mobile web application has a persistent cross-site scripting (XSS) vulnerability in path parameters that allows attackers to inject malic...

Feb 1, 2026
CVE-2022-50940 6.4

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting (XSS) vulnerability in the name parameter. Attackers can inject malicious scr...

Feb 1, 2026
CVE-2022-50941 6.4

BootCommerce 3.2.1 contains persistent cross-site scripting (XSS) vulnerabilities in guest order checkout input fields. Attackers can inject malicious...

Feb 1, 2026
CVE-2022-50942 5.4

CVE-2022-50942 is a client-side cross-site scripting vulnerability in Icinga Web 2.8.2 that allows attackers to inject malicious scripts through the i...

Feb 1, 2026
CVE-2022-50951 6.4

WiFi File Transfer 1.0.8 has a persistent cross-site scripting vulnerability where attackers can inject malicious JavaScript through file and folder n...

Feb 1, 2026
CVE-2022-50952 6.4

Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the profile name input field. Attackers can i...

Feb 1, 2026
CVE-2021-47917 6.4

Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious scri...

Feb 1, 2026
CVE-2021-47919 6.4

Simple CMS 2.1 contains a reflected cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can craft malicious URLs cont...

Feb 1, 2026
CVE-2021-47920 5.4

WebMO Job Manager 20.0 contains a reflected cross-site scripting vulnerability in search parameters that allows attackers to inject malicious JavaScri...

Feb 1, 2026