Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

type:xss — CVE vulnerabilities tagged 51336

51336 CVE security advisories tagged "type:xss" with AI Chinese analysis, CVSS, references and POCs.

The tag "type:xss" identifies Cross-Site Scripting, a critical web security vulnerability where attackers inject malicious scripts into trusted websites. This occurs when applications fail to properly validate or sanitize user input, allowing client-side code to execute within a victim’s browser session. The significance of XSS lies in its ability to bypass same-origin policies, enabling attackers to steal sensitive data like session cookies, credentials, or personal information, and to perform actions on behalf of the user. Typical scenarios include reflected XSS, where malicious links are sent via email or search results, and stored XSS, where scripts are permanently saved on target servers, such as in comment sections or forums. With over 48,000 associated CVEs, this widespread flaw remains a primary vector for web-based attacks, underscoring the necessity for robust input validation and output encoding practices in modern software development to protect user integrity and data confidentiality.

CVE ID Title CVSS Severity Published
CVE-2026-73848 Emlog: Stored XSS via Tag Name in Article Editor — emlog CWE-79 6.9 Medium 2026-09-04
CVE-2026-53758 Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized — emlog CWE-79 8.7 High 2026-09-04
CVE-2026-14466 Possible XSS in the SNS web administration panel — Stormshield Network Security CWE-79 4.3 Medium 2026-09-04
CVE-2026-8447 Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust — Langflow OSS CWE-79 6.1 Medium 2026-09-04
CVE-2026-19727 HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System — Library Information and Document Automation Program CWE-79 6.1 Medium 2026-09-04
CVE-2026-19057 Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System — Gastromenum Ticket and QR Menu System CWE-79 5.4 Medium 2026-09-04
CVE-2026-77818 Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System — Library Information and Document Automation Program CWE-79 6.1 Medium 2026-09-04
CVE-2026-18957 Stored XSS in Menulux Software's Menulux Portal — Menulux Portal CWE-79 5.4 Medium 2026-09-04
CVE-2026-85613 OpenPanel Unauthenticated XSS via SVG Favicon Proxy — openpanel CWE-79 8.2 High 2026-09-04
CVE-2026-85600 Grav Admin before 2.0.21 Stored XSS via username — grav CWE-79 5.4 Medium 2026-09-04
CVE-2026-85599 Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters — grav CWE-79 7.2 High 2026-09-04
CVE-2026-85598 Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages — grav CWE-79 6.4 Medium 2026-09-04
CVE-2026-85593 phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode — phpMyFAQ CWE-79 5.4 Medium 2026-09-04
CVE-2026-85590 phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable — phpMyFAQ CWE-308 7.1 High 2026-09-04
CVE-2026-85577 AVideo userLogin.php Reflected XSS via error parameter — AVideo CWE-79 5.4 Medium 2026-09-04
CVE-2026-85541 Interinfo|DreamMaker - Reflected Cross-site Scripting — DreamMaker CWE-79 5.4 Medium 2026-09-04
CVE-2026-27086 WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability — WoodMart CWE-79 6.5 Medium 2026-09-04
CVE-2026-80190 Apache Allura: Stored XSS via code repositories — Apache Allura CWE-79 - - 2026-09-04
CVE-2026-85229 Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057) — Apache SkyWalking CWE-79 - - 2026-09-04
CVE-2026-80180 Apache Allura: Stored XSS via markdown HTML processing — Apache Allura CWE-79 - - 2026-09-04
CVE-2026-85406 Eleveo Quality Management Conversation Review cross site scripting — Quality Management CWE-79 3.5 Low 2026-09-04
CVE-2026-85405 Eleveo Call Recording Software roleAddAction.do cross site scripting — Call Recording Software CWE-79 3.5 Low 2026-09-04
CVE-2026-85382 light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting — cms CWE-79 4.3 Medium 2026-09-04
CVE-2026-79418 EMX Gestion X ≤8.4 帮助聊天存储型XSS — n/a - - 2026-09-04
CVE-2026-79419 EMX Business Suite 8.4 及更早版本反射型XSS — n/a - - 2026-09-04
CVE-2026-78849 pfSense 2.8.1及以下版本跨站脚本漏洞 — n/a - - 2026-09-04
CVE-2026-75170 HubCore 14.1.1 未认证跨站脚本漏洞 — n/a - - 2026-09-04
CVE-2022-26961 Italtel NetMatch-S 5.0.0 多个存储型XSS漏洞 — n/a - - 2026-09-04
CVE-2022-35497 TM4WEB 21.4.0.4 会话配置错误致XSS — n/a - - 2026-09-04
CVE-2022-35499 TM4WEB 21.4.0.4 反射型XSS漏洞 — n/a - - 2026-09-04

Vulnerabilities classified as type:xss represent 51336 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.