Threats Tagged 'cwe-79'
View all threats tagged with 'cwe-79'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-79'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-17596: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Sonatype Nexus Repository 3CVE-2026-17596 0 Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0. Join the discussion | CVE Database V5 | 08/07/2026, 16:07:42 UTC Added: 08/07/2026, 16:26:45 UTC |
CVE-2026-48093: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in dartiss code-embedCVE-2026-48093 0 The Code Embed WordPress plugin before version 2.6.1 contains a stored Cross-Site Scripting (XSS) vulnerability via its external URL embed feature in post content. This flaw allows a contributor-level attacker to embed malicious JavaScript in a pending post that executes when an administrator or editor previews the post. The vulnerability arises because the plugin fetches and inserts remote URL content without proper output sanitization or capability checks. This issue is fixed in version 2.6.1. Join the discussion | CVE Database V5 | 08/07/2026, 15:46:31 UTC Added: 08/07/2026, 16:11:50 UTC |
CVE-2026-66494: CWE-284 Improper Access Control in joomshaper.com SP Page Builder extension for JoomlaCVE-2026-66494 0 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically.. Join the discussion | CVE Database V5 | 08/07/2026, 12:57:18 UTC Added: 08/07/2026, 13:26:45 UTC |
CVE-2026-48094: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in dartiss shareopenlyCVE-2026-48094 0 The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This variable is constructed from `home_url( add_query_arg( array(), $wp->request ) )` and is concatenated directly into an HTML `href` attribute on every singular post or page where the plugin's sharing link is displayed. WordPress's security handbook mandates that every URL placed in HTML output must be passed through `esc_url()`, which both HTML-encodes special characters (converting `"`, `<`, `>` into their safe HTML entity equivalents) and strips dangerous URI schemes such as `javascript:` and `data:`. The omission of this function means that if the `$url` value ever contains HTML-special characters or a dangerous URI scheme — through a `home_url` WordPress filter applied by another plugin or theme, through certain web server or hosting configurations, or through future code changes — the unescaped content will be injected verbatim into the rendered HTML of every post or page on the site. Version 1.2.1 contains a patch for the issue. Join the discussion | CVE Database V5 | 08/07/2026, 12:37:17 UTC Added: 08/07/2026, 12:56:47 UTC |
CVE-2026-54216: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in Tobit Laboratories AG TeamDavidCVE-2026-54216 0 Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:48:46 UTC Added: 08/07/2026, 10:12:17 UTC |
CVE-2026-15386: CWE-79 Cross-Site Scripting (XSS) in Meow GalleryCVE-2026-15386 0 The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:12 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-15245: CWE-79 Cross-Site Scripting (XSS) in BNE TestimonialsCVE-2026-15245 0 The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:12 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-15032: CWE-79 Cross-Site Scripting (XSS) in CommentsCVE-2026-15032 0 The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:10 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-14331: CWE-79 Cross-Site Scripting (XSS) in Subscribe2CVE-2026-14331 0 The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link. Join the discussion | CVE Database V5 | 08/07/2026, 06:00:10 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-42338: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in beaugunderson ip-addressCVE-2026-42338 0 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1. Join the discussion | GCVE Database | 05/12/2026, 19:43:16 UTC Added: 08/07/2026, 05:57:15 UTC |
Showing 1 to 10 of 542 results