Threats Tagged 'xss'
View all threats tagged with 'xss'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'xss'
Click on any threat for detailed analysis and mitigation recommendations
0 Readwise Reader for Android version 8.7.2 contains three stored cross-site scripting (XSS) vulnerabilities. These flaws allow attackers who can supply malicious documents or metadata to execute arbitrary JavaScript within the app's WebView context. The vulnerabilities arise from insufficient sanitization of document metadata fields, improper escaping of URL metadata, and permissive sanitization rules for SVG markup. Exploitation could compromise user data confidentiality and integrity, including access to stored documents, credentials, and session tokens. A patch addressing one of the issues is available in version 8.10.1. Users are advised to update when possible and exercise caution when adding content from untrusted sources. Join the discussion | CERT/CC | 09/25/2026, 16:27:54 UTC Added: 09/25/2026, 16:32:26 UTC |
CVE-2026-84942 is a high-severity cross-site scripting (XSS) vulnerability in AWS Amazon OpenSearch Service affecting the Vega expression function implementation in OpenSearch Dashboards. It allows a remote authenticated user with dashboard write permissions to execute arbitrary JavaScript in other users' browsers by saving a specially crafted Vega visualization. The vulnerability arises because the input validation routine failed to properly inspect nested arrays, allowing malicious function properties to bypass checks. This can lead to complete compromise of user sessions without impacting availability. Join the discussion | CVE Database V5 | 09/08/2026, 19:41:25 UTC Added: 09/08/2026, 19:52:45 UTC |
Bludit CMS 3.20.0 - Reflected Cross-Site ScriptingCVE-2026-41456 0 Bludit CMS 3.20.0 - Reflected Cross-Site Scripting Join the discussion | Exploit-DB RSS Feed | 09/02/2026, 00:00:00 UTC Added: 09/02/2026, 17:39:31 UTC |
0 CVE-2025-70336 is a medium severity stored cross-site scripting (XSS) vulnerability in PodcastGenerator version 3.2.9. It allows remote attackers with authenticated access to inject malicious scripts via the 'TITLE', 'SHORT DESCRIPTION', and 'LONG DESCRIPTION' fields when creating new live items. The injected payload executes when users view the 'View All Live Items' or 'Live Stream' pages, potentially compromising user sessions and data. Exploitation requires authentication and user interaction, limiting its immediate impact but still posing risks to confidentiality and integrity. No known exploits are currently in the wild, and no patches have been published yet. European organizations using PodcastGenerator 3.2.9, especially media and broadcasting entities, should be vigilant and apply strict input validation and output encoding as interim mitigations. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 01/28/2026, 15:35:57 UTC |
A stored cross-site scripting (XSS) vulnerability has been identified in Bludit CMS version 3.22.0. This vulnerability allows an attacker to inject malicious scripts that are stored and executed when viewed by other users. Join the discussion | Exploit-DB RSS Feed | 09/01/2026, 00:00:00 UTC Added: 09/01/2026, 17:59:45 UTC |
Multiple laser printers and multifunction printers (MFPs) that use Ricoh Web Image Monitor have a reflected cross-site scripting (XSS) vulnerability. This flaw allows malicious input to be reflected in web responses, potentially enabling script execution in users' browsers when interacting with the device's web interface. Join the discussion | JVN Japan | 08/31/2026, 06:30:15 UTC Added: 08/04/2026, 13:25:04 UTC |
0 CubeCart version 6.7.4 is affected by a Cross-Site Scripting (XSS) vulnerability. This type of vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. Join the discussion | Exploit-DB RSS Feed | 08/31/2026, 00:00:00 UTC Added: 08/31/2026, 17:43:04 UTC |
0 CubeCart version 6.7.4 contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts which are stored and later executed in users' browsers. Join the discussion | Exploit-DB RSS Feed | 08/31/2026, 00:00:00 UTC Added: 08/31/2026, 17:43:04 UTC |
0 C-MOR Video Surveillance version 6.0104 and earlier contains a Cross-Site Scripting (XSS) vulnerability. This flaw allows remote attackers to inject and execute arbitrary client-side scripts via the 'size' parameter in the ptzpreset.pml component and the 'anyparam' parameter in the show-movies.pml component. Exploit code is publicly available demonstrating how an attacker can trick authenticated users into executing malicious scripts. No active exploitation in the wild has been reported. Patch status is currently unconfirmed. Join the discussion | Exploit-DB RSS Feed | 08/31/2026, 00:00:00 UTC Added: 08/31/2026, 17:43:04 UTC |
0 CVE-2026-77811 is a stored cross-site scripting (XSS) vulnerability in the dashboards-observability plugin of OpenSearch Dashboards. It allows a remote authenticated user with write permissions to upload a custom integration containing arbitrary JavaScript. When other users access the affected static file endpoint, the malicious script executes in their browser, potentially performing actions on their behalf with their privileges. This affects self-managed OpenSearch Dashboards versions before 3.4 and 2.19.6, and Amazon OpenSearch Service versions before 3.3. The issue has been fixed in OpenSearch Dashboards versions 3.4 and 2.19.6 and all affected Amazon OpenSearch Service versions via service software updates. Users are advised to upgrade to these fixed versions or apply the managed service update. Workarounds include restricting write access and avoiding direct access to the vulnerable endpoint. Join the discussion | AWS Security Bulletins | 08/21/2026, 20:12:14 UTC Added: 08/21/2026, 20:20:41 UTC |
Showing 1 to 10 of 64 results