Search Results (50251 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92861 1 Wavedash 1 Ticket Ryutsu Center 2026-10-09 N/A
The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.
CVE-2026-103309 1 Wordpress-extensions 1 Gptranslate 2026-10-09 7.5 High
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
CVE-2026-104646 1 Wordpress-extensions 1 Image Photo Gallery Final Tiles Grid 2026-10-09 6.8 Medium
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
CVE-2026-89191 1 Sqlview 1 Sqlview Kris 2026-10-09 6.8 Medium
Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users.
CVE-2026-62127 2 Mediaron, Wordpress-extensions 2 Wp Plugin Info Card, Wp Plugin Info Card 2026-10-09 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MediaRon LLC WP Plugin Info Card wp-plugin-info-card allows Stored XSS.This issue affects WP Plugin Info Card: from n/a through 6.3.5.
CVE-2026-27420 2 Katieseaborn, Wordpress-extensions 2 Zotpress, Zotpress 2026-10-09 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.4.4.
CVE-2026-104077 1 Obsidian 1 Obsidian Desktop 2026-10-09 7.8 High
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.
CVE-2026-104078 1 Obsidian 1 Obsidian Desktop 2026-10-09 7.8 High
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.
CVE-2026-105269 1 Satel 1 Satel Netco Design 2026-10-09 6.8 Medium
Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.
CVE-2026-107796 1 Banq 1 Jivejdon 2026-10-09 6.1 Medium
Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.
CVE-2026-107798 1 Banq 1 Jivejdon 2026-10-09 5.4 Medium
jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.
CVE-2026-107799 1 Banq 1 Jivejdon 2026-10-09 5.4 Medium
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
CVE-2026-107801 1 Banq 1 Jivejdon 2026-10-09 5.4 Medium
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.
CVE-2026-107830 1 Banq 1 Jivejdon 2026-10-09 5.3 Medium
Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.
CVE-2026-105643 1 Ghost 1 Ghost 2026-10-09 7.3 High
Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.
CVE-2026-105644 1 Ghost 1 Ghost 2026-10-09 6.8 Medium
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.
CVE-2026-12380 1 Akilli Commerce Software Technologies Ltd. Co. 1 E-commerce Pack 2026-10-09 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue affects E-Commerce Pack: through 2026-10-06. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-106033 2 Ansible, Redhat 4 Ansible, Ansible Automation Platform, Hardened Images and 1 more 2026-10-09 5.4 Medium
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session.
CVE-2026-106444 1 Handlebarsjs 1 Handlebars 2026-10-09 4.7 Medium
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
CVE-2026-101158 1 Arista 1 Cloudvision Portal 2026-10-09 8.4 High
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.