İçeriğe atla
Noroxi

CWE-87 · 34 kayıt

Improper Neutralization of Alternate XSS Syntax

Bu sınıftaki CVE’ler

34 kayıt

  • CVE-2025-54369
    37İzleyin

    Node-SAML SAML Authentication Bypass

    KritikCVSS 9,3İstismar yokEPSS %1

    node-saml · node-saml24 Tem 2025

  • CVE-2026-33506
    35İzleyin

    DOM-Based XSS in Ory Polis Login Page

    YüksekCVSS 8,8İstismar yokEPSS %0

    ory · polis26 Mar 2026

  • CVE-2026-33510
    35İzleyin

    DOM-Based XSS in Homarr /auth/login Redirect

    YüksekCVSS 8,8İstismar yokEPSS %0

    homarr · homarr6 Nis 2026

  • CVE-2026-55237
    35İzleyin

    AutoGPT SignUp Page has DOM-Based XSS and Open Redirect

    YüksekCVSS 8,8İstismar yokEPSS %0

    significant-gravitas · autogpt18 Haz 2026

  • CVE-2026-40321
    32İzleyin

    DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

    YüksekCVSS 8,0İstismar yokEPSS %0

    dnnsoftware · dotnetnuke17 Nis 2026

  • CVE-2026-45314
    29İzleyin

    Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

    YüksekCVSS 7,4İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-22711
    27İzleyin

    Stored XSS through system messages in WikiLove

    OrtaCVSS 6,9İstismar yokEPSS %0

    the wikimedia foundation · mediawiki - wikilove extension7 Nis 2026

  • CVE-2023-35161
    25İzleyin

    XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    xwiki · xwiki23 Haz 2023

  • CVE-2023-35160
    25İzleyin

    XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    xwiki · xwiki23 Haz 2023

  • CVE-2023-35159
    25İzleyin

    XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    xwiki · xwiki23 Haz 2023

  • CVE-2023-35156
    25İzleyin

    XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    xwiki · xwiki23 Haz 2023

  • CVE-2023-35158
    25İzleyin

    XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    xwiki · xwiki23 Haz 2023

  • CVE-2025-14732
    25İzleyin

    Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API

    OrtaCVSS 6,4İstismar yokEPSS %0

    elemntor · elementor website builder – more than just a page builder7 Nis 2026

  • CVE-2024-3666
    25İzleyin

    Opal Estate Pro – Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

    OrtaCVSS 6,4İstismar yokEPSS %0

    wpopal · opal estate pro – property management and submission22 May 2024

  • CVE-2025-8561
    25İzleyin

    Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 6,4İstismar yokEPSS %0

    ovatheme · ova advent15 Eki 2025

  • CVE-2026-25688
    24İzleyin

    Apache Answer: XSS in AI Answer Rendering

    OrtaCVSS 6,1İstismar yokEPSS %1

    apache · answer9 Haz 2026

  • CVE-2024-3519
    24İzleyin

    Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang

    OrtaCVSS 6,1İstismar yokEPSS %0

    davidlingren · media library assistant21 May 2024

  • CVE-2021-40131
    21İzleyin

    Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerability

    OrtaCVSS 5,4İstismar yokEPSS %1

    cisco · common services platform collector18 Kas 2021

  • CVE-2022-20963
    21İzleyin

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker

    OrtaCVSS 5,4İstismar yokEPSS %0

    cisco · identity services engine4 Kas 2022

  • CVE-2026-42458
    21İzleyin

    Magento LTS: Reflected XSS - Import -> Data Flow (profiles)

    OrtaCVSS 5,3İstismar yokEPSS %0

    openmage · magento-lts15 May 2026

  • CVE-2024-8505
    21İzleyin

    WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

    OrtaCVSS 5,4İstismar yokEPSS %0

    connekthq · ajax load more2 Eki 2024

  • CVE-2026-79946
    21İzleyin

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutrali

    OrtaCVSS 5,3İstismar yokEPSS %0

    dell · secure connect gateway9 Eyl 2026

  • CVE-2024-4459
    21İzleyin

    Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles

    OrtaCVSS 5,4İstismar yokEPSS %0

    themesflat · themesflat addons for elementor6 Haz 2024

  • CVE-2024-25640
    21İzleyin

    Improper Neutralization of Alternate XSS Syntax in iris-web

    OrtaCVSS 5,4İstismar yokEPSS %0

    dfir-iris · iris19 Şub 2024

  • CVE-2024-2618
    21İzleyin

    Elementor Header & Footer Builder <= 1.6.26 - Authenticated (Contributor+) Stored Cross-Site Scripting

    OrtaCVSS 5,4İstismar yokEPSS %0

    brainstormforce · elementor header \& footer builder24 May 2024

Tüm zafiyet sınıfları