Tag

#Stored XSS

articleCRITICAL 10.0

Critical Stored XSS Vulnerability in SunEditor (CVE-2026-59167): A Deep Dive Analysis

A critical stored cross-site scripting (XSS) vulnerability, CVE-2026-59167, has been discovered in SunEditor, a popular WYSIWYG editor used in various web applications. With a CVSS score of 10, this vulnerability allows attackers to inject malicious scripts, potentially leading to data exposure, unauthorized browser-context actions, or other malicious activities. The vulnerability affects SunEditor versions prior to 2.47.11 and has been patched in the latest release. Organizations using SunEditor should immediately upgrade to version 2.47.11 or later to mitigate this critical threat.

1 source
articleMEDIUM 6.1

CVE-2026-82451: Stored Cross-Site Scripting in Formwork via Referer Header

A stored cross-site scripting (XSS) vulnerability exists in Formwork versions up to 2.3.14. The vulnerability is triggered by an unauthenticated attacker crafting a malicious Referer header, which is then stored and executed in the administrator's browser when viewing the Statistics panel. The CVSS score for this vulnerability is 6.1, indicating a medium severity. Organizations using Formwork should update to a patched version immediately.

1 source
articleHIGH 8.7

CVE-2026-75828: Stored Cross-Site Scripting Vulnerability in Grav CMS

A stored cross-site scripting (XSS) vulnerability exists in Grav CMS versions prior to 2.0.15. The vulnerability is caused by the detectXss() function failing to properly detect event handlers in unpaired quotes in unquoted attribute values. Authenticated editors can inject malicious event handlers, such as onerror=, that can execute in visitor browsers when page content is rendered. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. Organizations using Grav CMS should upgrade to version 2.0.15 or later to mitigate this vulnerability.

1 source
newsCRITICAL 9.0

Stored XSS Vulnerability in @apostrophecms/seo via Unsanitized Google Analytics / GTM ID

A stored XSS vulnerability exists in the @apostrophecms/seo package, allowing an editor-level user to inject malicious JavaScript into the site, affecting all visitors. The vulnerability is caused by unsanitized Google Analytics and Google Tag Manager IDs being injected into script tags.

1 source
articleCRITICAL 9.3

CVE-2026-65048: Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin

A critical vulnerability (CVE-2026-65048, CVSS 9.3) exists in the Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9, allowing unauthenticated stored cross-site scripting (XSS) attacks via the Repeatable Fieldset feature. An attacker can submit a crafted form with malicious script payloads, which execute in an administrator's browser when viewing submissions, enabling session-cookie theft, creation of administrator accounts, and arbitrary modification of site content. Immediate patching is recommended.

1 source
newsCRITICAL 9.0

CVE-2026-35198: Critical Stored XSS Vulnerability in HeyForm

A critical stored cross-site scripting (XSS) vulnerability exists in HeyForm, an open-source form builder, prior to version 3.0.0-rc.7. A low-privileged team member can inject malicious JavaScript, leading to account takeover through privilege escalation when a team owner views the form. Update to version 3.0.0-rc.7 or later to mitigate.

1 source
newsHIGH 8.8

CVE-2026-61875: Stored Cross-Site Scripting in luci-app-upnp via UPnP IGD AddPortMapping SOAP Requests

A stored cross-site scripting vulnerability exists in luci-app-upnp, allowing unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. This vulnerability has a CVSS score of 8.8 and is considered high severity. Affected users should update luci-app-upnp to the latest version.

1 source
blogCRITICAL 9.3

Understanding and Defending Against Stored Cross-Site Scripting (XSS) Vulnerabilities: A Deep Dive into CVE-2026-2342

This educational analysis delves into CVE-2026-2342, a stored cross-site scripting (XSS) vulnerability in OceanicSoft Informatics Systems Ltd.'s ValeApp. We will explore the root cause, attack surface, exploitation mechanics, real-world impact, and most importantly, defensive strategies to mitigate such threats.

1 source
blogMEDIUM 6.1

Understanding and Defending Against Stored Cross-Site Scripting (XSS) in AVideo TopMenu Plugin

This educational analysis covers CVE-2026-56347, a stored cross-site scripting vulnerability in the AVideo TopMenu plugin through version 26.0. The vulnerability allows attackers to inject malicious JavaScript through unescaped menu item fields, potentially stealing session cookies or performing unauthorized actions on all site visitors. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies.

1 source
blogHIGH 7.0

Understanding and Mitigating Stored XSS in n8n's Chat Trigger Node

A stored XSS vulnerability was discovered in n8n's Chat Trigger Node, allowing authenticated users with workflow edit access to inject arbitrary JavaScript. This could lead to code execution with the privileges of a logged-in user. The vulnerability has been patched in several n8n versions.

1 source