Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
Apache Answer: XSS in AI Answer Rendering
Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
n8n: XSS via MCP OAuth client
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
Stored XSS through system messages in WikiLove
ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection
DOM-Based XSS in Homarr /auth/login Redirect
YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
DOM-Based XSS in Ory Polis Login Page
Chamilo: Reflected XSS via page parameter
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
Node-SAML SAML Authentication Bypass
Contao is vulnerable to cross-site scripting in templates
Galette is vulnerable to Cross-site Scripting
Showing 1 - 20 of 1,000+ results