CWE-87 · 34 records
Improper Neutralization of Alternate XSS Syntax
CVEs in this class
34 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-54369No exploit | Node-SAML SAML Authentication Bypassnode-saml · node-saml · CWE-87 | Critical9.3 | — | 0.5% | Jul 24, 2025 |
35Monitor | CVE-2026-33506No exploit | DOM-Based XSS in Ory Polis Login Pageory · polis · CWE-87 | High8.8 | — | 0.4% | Mar 26, 2026 |
35Monitor | CVE-2026-33510No exploit | DOM-Based XSS in Homarr /auth/login Redirecthomarr · homarr · CWE-87 | High8.8 | — | 0.3% | Apr 6, 2026 |
35Monitor | CVE-2026-55237No exploit | AutoGPT SignUp Page has DOM-Based XSS and Open Redirectsignificant-gravitas · autogpt · CWE-87 | High8.8 | — | 0.3% | Jun 18, 2026 |
32Monitor | CVE-2026-40321No exploit | DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG uploaddnnsoftware · dotnetnuke · CWE-87 | High8.0 | — | 0.4% | Apr 17, 2026 |
29Monitor | CVE-2026-45314No exploit | Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/imageopenwebui · open webui · CWE-87 | High7.4 | — | 0.2% | May 15, 2026 |
27Monitor | CVE-2026-22711No exploit | Stored XSS through system messages in WikiLovethe wikimedia foundation · mediawiki - wikilove extension · CWE-87 | Medium6.9 | — | 0.3% | Apr 7, 2026 |
25Monitor | CVE-2023-35161Proof of concept | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication pagexwiki · xwiki · CWE-87 | Medium6.1 | — | 2.4% | Jun 23, 2023 |
25Monitor | CVE-2023-35160Proof of concept | XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit templatexwiki · xwiki · CWE-87 | Medium6.1 | — | 2.3% | Jun 23, 2023 |
25Monitor | CVE-2023-35159Proof of concept | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace templatexwiki · xwiki · CWE-87 | Medium6.1 | — | 2.2% | Jun 23, 2023 |
25Monitor | CVE-2023-35156Proof of concept | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete templatexwiki · xwiki · CWE-87 | Medium6.1 | — | 2.1% | Jun 23, 2023 |
25Monitor | CVE-2023-35158Proof of concept | XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore templatexwiki · xwiki · CWE-87 | Medium6.1 | — | 2.0% | Jun 23, 2023 |
25Monitor | CVE-2025-14732No exploit | Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST APIelemntor · elementor website builder – more than just a page builder · CWE-87 | Medium6.4 | — | 0.3% | Apr 7, 2026 |
25Monitor | CVE-2024-3666No exploit | Opal Estate Pro – Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scriptingwpopal · opal estate pro – property management and submission · CWE-87 | Medium6.4 | — | 0.3% | May 22, 2024 |
25Monitor | CVE-2025-8561No exploit | Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeovatheme · ova advent · CWE-87 | Medium6.4 | — | 0.2% | Oct 15, 2025 |
24Monitor | CVE-2026-25688No exploit | Apache Answer: XSS in AI Answer Renderingapache · answer · CWE-87 | Medium6.1 | — | 0.6% | Jun 9, 2026 |
24Monitor | CVE-2024-3519No exploit | Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via langdavidlingren · media library assistant · CWE-87 | Medium6.1 | — | 0.3% | May 21, 2024 |
21Monitor | CVE-2021-40131No exploit | Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerabilitycisco · common services platform collector · CWE-87 | Medium5.4 | — | 0.7% | Nov 18, 2021 |
21Monitor | CVE-2022-20963No exploit | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker cisco · identity services engine · CWE-87 | Medium5.4 | — | 0.5% | Nov 4, 2022 |
21Monitor | CVE-2026-42458No exploit | Magento LTS: Reflected XSS - Import -> Data Flow (profiles)openmage · magento-lts · CWE-87 | Medium5.3 | — | 0.4% | May 15, 2026 |
21Monitor | CVE-2024-8505No exploit | WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameterconnekthq · ajax load more · CWE-87 | Medium5.4 | — | 0.4% | Oct 2, 2024 |
21Monitor | CVE-2026-79946No exploit | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralidell · secure connect gateway · CWE-87 | Medium5.3 | — | 0.4% | Sep 9, 2026 |
21Monitor | CVE-2024-4459No exploit | Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titlesthemesflat · themesflat addons for elementor · CWE-87 | Medium5.4 | — | 0.3% | Jun 6, 2024 |
21Monitor | CVE-2024-25640No exploit | Improper Neutralization of Alternate XSS Syntax in iris-webdfir-iris · iris · CWE-87 | Medium5.4 | — | 0.3% | Feb 19, 2024 |
21Monitor | CVE-2024-2618No exploit | Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scriptingbrainstormforce · elementor header \& footer builder · CWE-87 | Medium5.4 | — | 0.3% | May 24, 2024 |
- CVE-2025-5436937Monitor
Node-SAML SAML Authentication Bypass
CriticalCVSS 9.3No exploitEPSS 1%node-saml · node-samlJul 24, 2025
- CVE-2026-3350635Monitor
DOM-Based XSS in Ory Polis Login Page
HighCVSS 8.8No exploitEPSS 0%ory · polisMar 26, 2026
- CVE-2026-3351035Monitor
DOM-Based XSS in Homarr /auth/login Redirect
HighCVSS 8.8No exploitEPSS 0%homarr · homarrApr 6, 2026
- CVE-2026-5523735Monitor
AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
HighCVSS 8.8No exploitEPSS 0%significant-gravitas · autogptJun 18, 2026
- CVE-2026-4032132Monitor
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
HighCVSS 8.0No exploitEPSS 0%dnnsoftware · dotnetnukeApr 17, 2026
- CVE-2026-4531429Monitor
Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
HighCVSS 7.4No exploitEPSS 0%openwebui · open webuiMay 15, 2026
- CVE-2026-2271127Monitor
Stored XSS through system messages in WikiLove
MediumCVSS 6.9No exploitEPSS 0%the wikimedia foundation · mediawiki - wikilove extensionApr 7, 2026
- CVE-2023-3516125Monitor
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page
MediumCVSS 6.1Proof of conceptEPSS 2%xwiki · xwikiJun 23, 2023
- CVE-2023-3516025Monitor
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
MediumCVSS 6.1Proof of conceptEPSS 2%xwiki · xwikiJun 23, 2023
- CVE-2023-3515925Monitor
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
MediumCVSS 6.1Proof of conceptEPSS 2%xwiki · xwikiJun 23, 2023
- CVE-2023-3515625Monitor
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
MediumCVSS 6.1Proof of conceptEPSS 2%xwiki · xwikiJun 23, 2023
- CVE-2023-3515825Monitor
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
MediumCVSS 6.1Proof of conceptEPSS 2%xwiki · xwikiJun 23, 2023
- CVE-2025-1473225Monitor
Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
MediumCVSS 6.4No exploitEPSS 0%elemntor · elementor website builder – more than just a page builderApr 7, 2026
- CVE-2024-366625Monitor
Opal Estate Pro – Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 6.4No exploitEPSS 0%wpopal · opal estate pro – property management and submissionMay 22, 2024
- CVE-2025-856125Monitor
Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 6.4No exploitEPSS 0%ovatheme · ova adventOct 15, 2025
- CVE-2026-2568824Monitor
Apache Answer: XSS in AI Answer Rendering
MediumCVSS 6.1No exploitEPSS 1%apache · answerJun 9, 2026
- CVE-2024-351924Monitor
Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang
MediumCVSS 6.1No exploitEPSS 0%davidlingren · media library assistantMay 21, 2024
- CVE-2021-4013121Monitor
Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerability
MediumCVSS 5.4No exploitEPSS 1%cisco · common services platform collectorNov 18, 2021
- CVE-2022-2096321Monitor
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker
MediumCVSS 5.4No exploitEPSS 0%cisco · identity services engineNov 4, 2022
- CVE-2026-4245821Monitor
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
MediumCVSS 5.3No exploitEPSS 0%openmage · magento-ltsMay 15, 2026
- CVE-2024-850521Monitor
WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter
MediumCVSS 5.4No exploitEPSS 0%connekthq · ajax load moreOct 2, 2024
- CVE-2026-7994621Monitor
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutrali
MediumCVSS 5.3No exploitEPSS 0%dell · secure connect gatewaySep 9, 2026
- CVE-2024-445921Monitor
Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles
MediumCVSS 5.4No exploitEPSS 0%themesflat · themesflat addons for elementorJun 6, 2024
- CVE-2024-2564021Monitor
Improper Neutralization of Alternate XSS Syntax in iris-web
MediumCVSS 5.4No exploitEPSS 0%dfir-iris · irisFeb 19, 2024
- CVE-2024-261821Monitor
Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%brainstormforce · elementor header \& footer builderMay 24, 2024