Search Results (47709 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65446 2 Wordpress, Wp Chill 2 Wordpress, Kali Forms 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-53667 1 Remix-run 1 React-router 2026-07-28 6.9 Medium
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
CVE-2026-53668 1 Remix-run 1 React-router 2026-07-28 6.9 Medium
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
CVE-2026-65438 2 Kofimokome, Wordpress 2 Message Filter For Contact Form 7, Wordpress 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65440 2 Roxnor, Wordpress 2 Getgenie, Wordpress 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65441 2 Nexcess, Wordpress 2 Givewp, Wordpress 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-51081 2026-07-28 6.1 Medium
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
CVE-2026-65448 2026-07-27 6.5 Medium
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.
CVE-2026-65443 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65437 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-61957 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-47410 1 Mervinpraison 1 Praisonai 2026-07-27 9.8 Critical
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default value of `PLATFORM_ENV` is `"dev"`, so the check is silently bypassed in any deployment that does not explicitly opt out. The attacker reads the literal from this public source file, mints a JWT with arbitrary `sub` and `email` claims, and authenticates as any existing user (including workspace owners and admins). PraisonAI Platform version 0.1.4 patches the issue.
CVE-2026-8982 1 Autel 1 Maxicharger Single Charger 2026-07-27 N/A
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
CVE-2026-8983 1 Autel 1 Maxicharger Single Charger 2026-07-27 N/A
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.
CVE-2026-59559 2 Themewant, Wordpress 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress 2026-07-27 6.5 Medium
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.
CVE-2026-65561 2 Miniorange, Wordpress 2 Wordpress Social Login And Register, Wordpress 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
CVE-2026-65563 2 Themeisle, Wordpress 2 Orbit Fox By Themeisle, Wordpress 2026-07-27 5.9 Medium
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
CVE-2026-66434 2 Sayontan Sinha, Wordpress 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Wordpress 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
CVE-2026-66475 2 Acowebs, Wordpress 2 Checkout Field Editor For Woocommerce – Checkout Manager, Wordpress 2026-07-27 5.9 Medium
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.
CVE-2026-66825 2026-07-27 N/A
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to supply or influence node or edge property data could provide a malicious value using the javascript: scheme, including variants obfuscated with whitespace or control characters. If a user clicked the generated property link, attacker-controlled JavaScript could execute in the context of the Pivotick application. Successful exploitation could allow the attacker to access information available to the victim’s browser session or perform actions with the victim’s privileges. The vulnerability was addressed by normalizing property values and preventing URLs with non-allowlisted schemes from being rendered as clickable links.