Threats Tagged 'cwe-87'
View all threats tagged with 'cwe-87'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-87'
Click on any threat for detailed analysis and mitigation recommendations
0 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. Join the discussion | CVE Database V5 | 09/09/2026, 15:11:22 UTC Added: 09/09/2026, 15:22:45 UTC |
0 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), Sane::sanitizeFile(), or file sanitizeContents() with untrusted input allow malicious markup injected as children of an unknown HTML or XML tag to pass through Dom::sanitize() without being correctly sanitized, causing stored cross-site scripting. This issue is fixed in versions 4.9.4 and 5.4.4. Join the discussion | CVE Database V5 | 07/09/2026, 18:34:29 UTC Added: 07/09/2026, 19:18:15 UTC |
0 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to `router.push`. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the context of their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim. Version 0.6.62 patches the issue. Join the discussion | CVE Database V5 | 06/18/2026, 16:21:40 UTC Added: 06/18/2026, 16:36:21 UTC |
0 md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary JavaScript execution in the context of the affected domain. This issue has been patched in version 1.10.3. Join the discussion | CVE Database V5 | 06/09/2026, 16:09:29 UTC Added: 06/09/2026, 16:26:00 UTC |
0 CVE-2026-25688 is a medium severity vulnerability in Apache Answer up to version 2.0.0. It involves improper neutralization of alternate cross-site scripting (XSS) syntax in AI-generated response content, which is rendered in the browser without proper sanitization. This flaw allows malicious scripts to execute when the content is viewed. The issue is fixed in version 2.0.1. Join the discussion | CVE Database V5 | 06/09/2026, 07:32:23 UTC Added: 06/09/2026, 09:55:54 UTC |
0 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -> System -> Import/Export -> Dataflow - Profiles. This vulnerability is fixed in 20.18.0. Join the discussion | CVE Database V5 | 05/15/2026, 17:02:42 UTC Added: 05/15/2026, 17:22:45 UTC |
0 CVE-2026-42235 is a high-severity vulnerability in the n8n workflow automation platform affecting versions prior to 1.123.32, 2.17.4, and 2.18.1. It allows an unauthenticated attacker to register a malicious OAuth client with a crafted client_name that leads to improper neutralization of alternate XSS syntax. When a victim user authorizes the OAuth consent and another user revokes access, a toast notification renders injected script, enabling execution of arbitrary JavaScript in the victim's authenticated session. This can result in credential and session token theft, workflow manipulation, or privilege escalation. Join the discussion | CVE Database V5 | 05/04/2026, 18:38:09 UTC Added: 05/04/2026, 18:51:29 UTC |
0 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Join the discussion | CVE Database V5 | 04/17/2026, 21:10:33 UTC Added: 04/17/2026, 21:38:06 UTC |
Elementor Website Builder plugin for WordPress up to version 3.35.5 contains a stored cross-site scripting (XSS) vulnerability. Authenticated users with Contributor-level access or higher can inject malicious scripts via several widget parameters. These scripts execute when any user views the affected page. The vulnerability arises from insufficient input sanitization and output escaping. The CVSS score is 6.4, indicating a medium severity level. No official patch or remediation guidance is currently available. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 04/08/2026, 01:24:43 UTC Added: 04/08/2026, 04:31:38 UTC |
0 CVE-2026-22711 is a medium severity vulnerability in the Wikimedia Foundation's Mediawiki Wikilove Extension involving improper neutralization of alternate cross-site scripting (XSS) syntax. This flaw allows XSS attacks due to insufficient sanitization of input. The issue has been fixed in the master branch and release branches for MediaWiki versions 1.43, 1.44, and 1.45. No known exploits are reported in the wild. The vulnerability has a CVSS 4.0 base score of 6.9, indicating a moderate risk level. Join the discussion | CVE Database V5 | 04/07/2026, 18:39:37 UTC Added: 04/07/2026, 22:38:03 UTC |
Showing 1 to 10 of 28 results