Skip to content
Noroxi

CWE-87 · 34 records

Improper Neutralization of Alternate XSS Syntax

CVEs in this class

34 records

  • Node-SAML SAML Authentication Bypass

    CriticalCVSS 9.3No exploitEPSS 1%

    node-saml · node-samlJul 24, 2025

  • DOM-Based XSS in Ory Polis Login Page

    HighCVSS 8.8No exploitEPSS 0%

    ory · polisMar 26, 2026

  • DOM-Based XSS in Homarr /auth/login Redirect

    HighCVSS 8.8No exploitEPSS 0%

    homarr · homarrApr 6, 2026

  • AutoGPT SignUp Page has DOM-Based XSS and Open Redirect

    HighCVSS 8.8No exploitEPSS 0%

    significant-gravitas · autogptJun 18, 2026

  • DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

    HighCVSS 8.0No exploitEPSS 0%

    dnnsoftware · dotnetnukeApr 17, 2026

  • Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

    HighCVSS 7.4No exploitEPSS 0%

    openwebui · open webuiMay 15, 2026

  • Stored XSS through system messages in WikiLove

    MediumCVSS 6.9No exploitEPSS 0%

    the wikimedia foundation · mediawiki - wikilove extensionApr 7, 2026

  • XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page

    MediumCVSS 6.1Proof of conceptEPSS 2%

    xwiki · xwikiJun 23, 2023

  • XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template

    MediumCVSS 6.1Proof of conceptEPSS 2%

    xwiki · xwikiJun 23, 2023

  • XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template

    MediumCVSS 6.1Proof of conceptEPSS 2%

    xwiki · xwikiJun 23, 2023

  • XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template

    MediumCVSS 6.1Proof of conceptEPSS 2%

    xwiki · xwikiJun 23, 2023

  • XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template

    MediumCVSS 6.1Proof of conceptEPSS 2%

    xwiki · xwikiJun 23, 2023

  • Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

    MediumCVSS 6.4No exploitEPSS 0%

    elemntor · elementor website builder – more than just a page builderApr 7, 2026

  • CVE-2024-3666
    25Monitor

    Opal Estate Pro – Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 6.4No exploitEPSS 0%

    wpopal · opal estate pro – property management and submissionMay 22, 2024

  • CVE-2025-8561
    25Monitor

    Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 6.4No exploitEPSS 0%

    ovatheme · ova adventOct 15, 2025

  • Apache Answer: XSS in AI Answer Rendering

    MediumCVSS 6.1No exploitEPSS 1%

    apache · answerJun 9, 2026

  • CVE-2024-3519
    24Monitor

    Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang

    MediumCVSS 6.1No exploitEPSS 0%

    davidlingren · media library assistantMay 21, 2024

  • Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    cisco · common services platform collectorNov 18, 2021

  • A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker

    MediumCVSS 5.4No exploitEPSS 0%

    cisco · identity services engineNov 4, 2022

  • Magento LTS: Reflected XSS - Import -> Data Flow (profiles)

    MediumCVSS 5.3No exploitEPSS 0%

    openmage · magento-ltsMay 15, 2026

  • CVE-2024-8505
    21Monitor

    WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

    MediumCVSS 5.4No exploitEPSS 0%

    connekthq · ajax load moreOct 2, 2024

  • Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutrali

    MediumCVSS 5.3No exploitEPSS 0%

    dell · secure connect gatewaySep 9, 2026

  • CVE-2024-4459
    21Monitor

    Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles

    MediumCVSS 5.4No exploitEPSS 0%

    themesflat · themesflat addons for elementorJun 6, 2024

  • Improper Neutralization of Alternate XSS Syntax in iris-web

    MediumCVSS 5.4No exploitEPSS 0%

    dfir-iris · irisFeb 19, 2024

  • CVE-2024-2618
    21Monitor

    Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    brainstormforce · elementor header \& footer builderMay 24, 2024

All vulnerability classes