Robuta

https://owasp.org/www-community/attacks/xss/ Cross Site Scripting (XSS) | OWASP Foundation Cross Site Scripting (XSS) on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software. cross site scriptingxssowaspfoundation https://portswigger.net/web-security/cross-site-scripting/cheat-sheet Cross-Site Scripting (XSS) Cheat Sheet - 2026 Edition | Web Security Academy Interactive cross-site scripting (XSS) cheat sheet for 2026, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors. cross site scriptingcheat sheetweb securityxss https://thespanner.co.uk/2012/05/01/xss-technique-without-parentheses XSS technique without parentheses - The Spanner This is a very old technique I discovered years ago which I used to bypass a filter and it's pretty awesome. It might come in handy to bypass a WAF or filter... xsstechniquewithoutparenthesesspanner https://web.dev/articles/strict-csp Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP) | Articles | web.dev Sep 13, 2024 - Learn how to deploy a CSP based on script nonces or hashes as a defense-in-depth against cross-site scripting. https://jsoup.org/ jsoup: Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety Open source Java HTML parser, with the best of HTML5 DOM methods and CSS selectors, for easy data extraction. html parserbuilt for https://github.com/mybb/mybb/security/advisories/GHSA-p766-qqxv-rfc2 Buddy/ignore list username XSS · Advisory · mybb/mybb · GitHub GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects. ignore listbuddyusernamexssadvisory https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8 Visual editor persistent XSS · Advisory · mybb/mybb · GitHub GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects. visual editorpersistentxssadvisorymybb https://advisories.gitlab.com/maven/org.keycloak/keycloak-core/CVE-2024-4028/ Keycloak allows cross-site scripting (XSS) | GitLab Advisory Database (GLAD) CVE-2024-4028 Keycloak allows cross-site scripting (XSS): A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious... cross site scriptingkeycloakallowsxssgitlab https://thehackernews.com/2012/01/cross-site-scripting-xss-vulnerability.html Cross Site Scripting (XSS) Vulnerability in Google Cross Site Scripting (XSS) Vulnerability in Google | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against... cross site scriptingxssvulnerabilitygoogle https://advisories.gitlab.com/npm/trix/CVE-2024-53847/ Trix editor subject to XSS vulnerabilities on copy & paste | GitLab Advisory Database (GLAD) https://ndevtk.github.io/writeups/2026/03/19/google-xss-3/?ref=rosecurify.com Google XSS part 3 | Writeups Mar 19, 2026 - XSS in Firebase Studio (Awarded $7500, Deprecated) googlexsspartwriteups https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34605/ SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon,... CVE-2026-34605 SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated): The SanitizeSVG function... https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1241938380000&hl=fr_CA Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template... Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio... https://advisories.gitlab.com/npm/n8n/CVE-2025-61914/ n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox | GitLab... CVE-2025-61914 n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox: A stored Cross-Site Scripting (XSS) vulnerability may... https://advisories.gitlab.com/golang/github.com/quantumnous/new-api/CVE-2026-25802/ New API has Potential XSS in its MarkdownRenderer component | GitLab Advisory Database (GLAD) CVE-2026-25802 New API has Potential XSS in its MarkdownRenderer component: A potential unsafe operation occurs in component MarkdownRenderer.jsx, allowing for... https://advisories.gitlab.com/npm/n8n/CVE-2025-58177/ Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter | GitLab Advisory... CVE-2025-58177 Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter: A stored Cross-Site Scripting (XSS) vulnerability was identified in... https://advisories.gitlab.com/pypi/mayan-edms/CVE-2022-47419/ Mayan EDMS DMS XSS vulnerability | GitLab Advisory Database (GLAD) CVE-2022-47419 Mayan EDMS DMS XSS vulnerability: An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the... mayan edmsxssvulnerabilitygitlabadvisory https://advisories.gitlab.com/composer/pimcore/pimcore/CVE-2023-2332/ Cross-site Scripting (XSS) in Conditions tab of Pricing Rules | GitLab Advisory Database (GLAD) CVE-2023-2332 Cross-site Scripting (XSS) in Conditions tab of Pricing Rules: This vulnerability has the potential to steal a user's cookie and gain... cross site scripting https://advisories.gitlab.com/npm/@nuxtjs/mdc/CVE-2025-54075/ Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering | GitLab... CVE-2025-54075 Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering: A remote script-inclusion / stored XSS vulnerability in... https://advisories.gitlab.com/maven/com.liferay/com.liferay.document.library.web/CVE-2022-42113/ Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module | GitLab Advisory... CVE-2022-42113 Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module: A Cross-site scripting (XSS) vulnerability in Document Library... https://advisories.gitlab.com/composer/thorsten/phpmyfaq/CVE-2025-68951/ phpMyFAQ has Stored XSS in user list via admin-managed display_name | GitLab Advisory Database... CVE-2025-68951 phpMyFAQ has Stored XSS in user list via admin-managed display_name: A stored cross-site scripting (XSS) vulnerability allows an attacker to... https://advisories.gitlab.com/pypi/octoprint/CVE-2024-28237/ XSS via the "Snapshot Test" feature in Classic Webcam plugin settings | GitLab Advisory Database... CVE-2024-28237 XSS via the "Snapshot Test" feature in Classic Webcam plugin settings: OctoPrint versions up until and including 1.9.3 contain a vulnerability... https://taosecurity.blogspot.com/2007/07/review-of-xss-attacks-posted.html?showComment=1252258935265 Review of XSS Attacks Posted Richard Bejtlich's blog on digital security, strategic thought, and military history. xss attacksreviewposted https://www.ibm.com/support/pages/apar/PI93897 PI93897: PERSISTENT CROSS SITE SCRIPTING (XSS) ISSUE IN COGNOS 10.2.2 XSS error (see screenshot in testcase) cross site scriptingpersistent https://advisories.gitlab.com/golang/github.com/openziti/zrok/v2/CVE-2026-40302/ zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering |... CVE-2026-40302 zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering: Summary The proxyUi template engine uses Go's... github oauth https://vuxml.freebsd.org/freebsd/c2c89dea-2859-4231-8f3b-012be0d475ff.html VuXML: py-django-photologue -- XSS vulnerability vuxmlpydjangoxssvulnerability https://advisories.gitlab.com/composer/starcitizentools/citizen-skin/CVE-2025-62508/ Citizen vulnerable to stored XSS in sticky header button messages | GitLab Advisory Database (GLAD) CVE-2025-62508 Citizen vulnerable to stored XSS in sticky header button messages: The JS implementation for copying button labels to the sticky header in the... https://advisories.gitlab.com/composer/shopware/shopware/GHSA-9v82-vcjx-m76j/ Shopware: Reflective Cross Site-Scripting (XSS) in CMS components | GitLab Advisory Database (GLAD) GHSA-9v82-vcjx-m76j Shopware: Reflective Cross Site-Scripting (XSS) in CMS components: When an application uses input fields, it is important that user input... cross site scripting https://advisories.gitlab.com/maven/org.xwiki.platform/xwiki-platform-flamingo-theme-ui/CVE-2022-29251/ Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | GitLab Advisory... CVE-2022-29251 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS): XWiki Platform Flamingo Theme UI is a tool that allows... https://advisories.gitlab.com/pypi/mezzanine/CVE-2020-19002/ Mezzanine Cross Site Scripting (XSS) vulnerability | GitLab Advisory Database (GLAD) CVE-2020-19002 Mezzanine Cross Site Scripting (XSS) vulnerability: Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary... cross site scriptingmezzaninexssvulnerabilitygitlab https://userapps.support.sap.com/sap/support/knowledge/en/2584438 2584438 - Vulnerability scan against Fiori Launchpad reports XSS in PAGE_BUILDER service | SAP... https://advisories.gitlab.com/composer/opensource-workshop/connect-cms/CVE-2026-32278/ Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin | GitLab... CVE-2026-32278 Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin: A Stored Cross-site Scripting (XSS) issue exists in the... https://advisories.gitlab.com/npm/@pdfme/schemas/GHSA-xgx4-2wgv-4jhm/ PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel |... GHSA-xgx4-2wgv-4jhm PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel: The multiVariableText property panel in... https://pastebin.com/B8JBzaE2 [MINI EXPLOIT] Wordpress Theme Photocrati 4.x.x - SQLI & XSS - Pastebin.com Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time. wordpress thememiniexploitphotocrati https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43823/ Liferay Portal is vulnerable to XSS through its Commerce Search Result widget | GitLab Advisory... CVE-2025-43823 Liferay Portal is vulnerable to XSS through its Commerce Search Result widget: Cross-site Scripting (XSS) vulnerability in the Commerce Search... https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-25483/ Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration |... CVE-2026-25483 Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration: A stored XSS vulnerability exists in Craft... https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/MCYGUEP5HPMTY53K76E3DZQ5UFL4MRHH/ Re: [aur-general] Moving xss-lock to community - Aur-general - lists.archlinux.org general movingto communityaurxss https://advisories.gitlab.com/maven/org.geoserver.web/gs-web-app/CVE-2025-21621/ GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML... CVE-2025-21621 GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format: A reflected cross-site scripting (XSS)... https://advisories.gitlab.com/npm/open-webui/CVE-2025-64495/ Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled... CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE: The functionality that... https://advisories.gitlab.com/nuget/dotnetnuke.core/CVE-2026-24837/ DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal | GitLab Advisory... CVE-2026-24837 DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal: A module friendly name could include scripts that will run... https://groups.google.com/g/ruby-security-ann/c/5ZI1-H5OoIM/m/ZNq4FoR2GnIJ [CVE-2013-6416] XSS Vulnerability in simple_format helper cvexssvulnerabilitysimpleformat https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2025-60880/ Bagisto is vulnerable to XSS through Admin Panel's product creation path | GitLab Advisory Database... CVE-2025-60880 Bagisto is vulnerable to XSS through Admin Panel's product creation path: An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6... https://patchstack.com/database/wordpress/plugin/cartflows/vulnerability/wordpress-cartflows-plugin-2-0-1-cross-site-scripting-xss-vulnerability Cross Site Scripting (XSS) in WordPress CartFlows Plugin - Patchstack Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues. cross site scriptingxsswordpresscartflowsplugin https://docs.rs/crate/cargo-xss-testing/latest cargo-xss-testing 0.4.6 - Docs.rs cargoxsstestingdocsrs https://advisories.gitlab.com/composer/silverstripe/framework/GHSA-r32j-mr8p-hfp8/ Silverstripe XSS in TreeDropdownField and TreeMultiSelectField | GitLab Advisory Database (GLAD) GHSA-r32j-mr8p-hfp8 Silverstripe XSS in TreeDropdownField and TreeMultiSelectField: A cross-site scripting vulnerability has been discovered in the... silverstripexssgitlabadvisorydatabase https://advisories.gitlab.com/composer/craftcms/commerce/CVE-2026-29175/ Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking |... CVE-2026-29175 Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking: Stored XSS vulnerabilities exist in the... https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/CVE-2024-29891/ ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass |... CVE-2024-29891 ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass: ZITADEL users can upload their own avatar... https://advisories.gitlab.com/npm/n8n/GHSA-3c7f-5hgj-h279/ n8n has XSS in Chat Trigger Node through Custom CSS | GitLab Advisory Database (GLAD) GHSA-3c7f-5hgj-h279 n8n has XSS in Chat Trigger Node through Custom CSS: An authenticated user with permission to create or modify workflows could inject... https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1238989020000&hl=fr_CA Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template... Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio... https://advisories.gitlab.com/maven/org.webjars.npm/jquery-ui/CVE-2022-31160/ jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label |... CVE-2022-31160 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label: Initializing a checkboxradio widget on an... https://advisories.gitlab.com/cargo/vaultwarden/CVE-2024-55226/ Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability | GitLab Advisory... CVE-2024-55226 Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability: Vaultwarden v1.32.5 was discovered to contain an authenticated... cross site scriptingvaultwardenauthenticatedreflectedxss https://advisories.gitlab.com/composer/openmage/magento-lts/GHSA-gp6m-fq6h-cjcx/ Magento LTS vulnerable to stored XSS in admin file form | GitLab Advisory Database (GLAD) GHSA-gp6m-fq6h-cjcx Magento LTS vulnerable to stored XSS in admin file form: Summary OpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability... https://knowledge.broadcom.com/external/article/276324/identity-manager-or-identity-portal-vuln.html Identity Manager or Identity Portal Vulnerability regarding XSS and Clickjacking identity managerportalvulnerabilityregardingxss https://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html Quick.Forum 'topic field' XSS and 'page' & 'iCategory' SQL injection forum topicquickfieldxsssql https://patchstack.com/database/wordpress/plugin/astra-widgets/vulnerability/wordpress-astra-widgets-plugin-1-2-14-stored-cross-site-scripting-xss-vulnerability Cross Site Scripting (XSS) in WordPress Astra Widgets Plugin - Patchstack Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues. cross site scriptingxsswordpressastrawidgets https://bughunters.google.com/reports/vrp/qZmd7EJHp/report Reflected Cross-Site Scripting (XSS) on Google Acquisition Domain | Google Bug Hunters Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse. cross site scriptingon googlereflectedxss https://advisories.gitlab.com/golang/github.com/casdoor/casdoor/CVE-2026-5468/ Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml | GitLab Advisory Database... CVE-2026-5468 Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml: A security flaw has been discovered in Casdoor 2.356.0. This affects the... https://www.drupal.org/node/2459315 Crumbs - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-082 | Drupal.org Jun 11, 2015 - Advisory ID: DRUPAL-SA-CONTRIB-2015-082 Project: Crumbs (third-party module) Version: 7.x Date: 2015-March-25 Security risk: 13/25 ( Moderately Critical)... cross site scripting https://speakerdeck.com/lmt_swallow/gimme-a-bit-exploring-attacks-in-the-post-xss-world "Gimme a bit!" - Exploring Attacks in the "Post-XSS" World - Speaker Deck Presented at: https://shibuyaxss.connpass.com/event/128168/ in the posta bit https://advisories.gitlab.com/npm/astro/CVE-2025-59837/ Astro's bypass of image proxy domain validation leads to SSRF and potential XSS | GitLab Advisory... CVE-2025-59837 Astro's bypass of image proxy domain validation leads to SSRF and potential XSS: This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The... https://advisories.gitlab.com/npm/koa/CVE-2025-32379/ Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function | GitLab Advisory... cross site scripting https://4t64ubva.xssy.uk/ Unicode XSS unicodexss https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1239706440000&hl=es Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template... Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio... https://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html?showComment=1238586540000&hl=fr_CA Google Online Security Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template... Posted by Jad S. Boutros, Security Team Building on our earlier posts on defenses against web application flaws [ "Automating Web Applicatio... https://advisories.gitlab.com/golang/code.vikunja.io/api/CVE-2026-25935/ Vikunja Vulnerable to XSS Via Task Preview | GitLab Advisory Database (GLAD) CVE-2026-25935 Vikunja Vulnerable to XSS Via Task Preview: The task preview component creates a unparented div. The div's innerHtml is set to the unescaped... vikunjavulnerablexssvia https://developer.joomla.org/security-centre/570-20131101-core-xss-vulnerability.html [20131101] Core XSS Vulnerability corexssvulnerability https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24412/ Magento Stored Cross-Site Scripting (XSS) Vulnerability | GitLab Advisory Database (GLAD) CVE-2025-24412 Magento Stored Cross-Site Scripting (XSS) Vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and... cross site scriptingmagentostored https://groups.google.com/g/rubyonrails-security/c/SKs_SiwWGQ8 XSS Vulnerability in Ruby on Rails xssvulnerabilityrubyrails https://advisories.gitlab.com/pypi/omero-web/GHSA-j4gv-6x9v-v23g/ OMERO.web uses jquery-form library, which may be vulnerable to XSS attack | GitLab Advisory... GHSA-j4gv-6x9v-v23g OMERO.web uses jquery-form library, which may be vulnerable to XSS attack: OMERO.web uses the jquery-form library throughout to handle form... https://patchstack.com/database/wordpress/plugin/ultimate_vc_addons/vulnerability/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-20-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability-4 Cross Site Scripting (XSS) in WordPress Ultimate Addons for WPBakery Page Builder Plugin -... Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues. cross site scripting https://advisories.gitlab.com/composer/phpmyfaq/phpmyfaq/CVE-2026-34729/ phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes() | GitLab Advisory Database... CVE-2026-34729 phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes(): The sanitization pipeline for FAQ content is: Filter::filterVar($input,... https://developer.joomla.org/security-centre/937-20240703-core-xss-in-stringhelper-truncate-method.html [20240703] - Core - XSS in StringHelper::truncate method corexsstruncatemethod https://docs.google.com/presentation/d/1gj98wzYiZ9K_JEXYon94jnF4jzacGgO0vDlLJR1PtA4/edit [CS161 FA22] Lecture 14: XSS and UI Attacks - Google Slides XSS and UI Attacks CS 161 Fall 2022 - Lecture 14 lecturexssuiattacksgoogle https://advisories.gitlab.com/npm/ckeditor5-premium-features/CVE-2025-25299/ Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package | GitLab Advisory... CVE-2025-25299 Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package: During a recent internal audit, we identified a Cross-Site... cross site scripting https://en-ca.wordpress.org/plugins/tags/xss-protection/ Plugins categorized as xss protection | WordPress.org English (Canada) pluginscategorizedxssprotectionwordpress https://advisories.gitlab.com/maven/org.jenkins-ci.plugins/bart/CVE-2022-45387/ Jenkins BART Plugin vulnerable to cross-site scripting (XSS) | GitLab Advisory Database (GLAD) CVE-2022-45387 Jenkins BART Plugin vulnerable to cross-site scripting (XSS): Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build... cross site scripting https://advisories.gitlab.com/nuget/dotnetnuke.core/CVE-2025-59546/ DNN Vulnerable to Stored XSS Using Backend Admin Credentials | GitLab Advisory Database (GLAD) CVE-2025-59546 DNN Vulnerable to Stored XSS Using Backend Admin Credentials: Users that can edit modules could set a title that includes scripts. https://nomoreroot.blogspot.com/2008/08/ie8-xss-filter.html No More Root: IE8 XSS filter Since IE8 beta2 is out I downloaded and installed it, I wanted to take a look at the brand new XSS filter ( See here *1). Basically I wanted... no morerootxssfilter https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-39846/ SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table... CVE-2026-39846 SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions: A malicious note synced to another user... https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-gutenberg/vulnerability/wordpress-spectra-plugin-2-19-14-authenticated-contributor-stored-cross-site-scripting-via-custom-css-vulnerability Cross Site Scripting (XSS) in WordPress Spectra Plugin - Patchstack Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues. cross site scriptingxsswordpressspectraplugin https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2026-34448/ SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command... CVE-2026-34448 SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client: An attacker who can... https://bughunters.google.com/reports/vrp/M1xsjw9js/comments XSS in https://run.qwiklabs.com/my_account | Google Bug Hunters Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse. my accountxsshttpsrunqwiklabs https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-5370/ Krayin CRM is vulnerable to Cross-site Scripting (XSS) | GitLab Advisory Database (GLAD) CVE-2026-5370 Krayin CRM is vulnerable to Cross-site Scripting (XSS): A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function... cross site scripting https://advisories.gitlab.com/composer/getkirby/cms/CVE-2025-65012/ Kirby CMS has cross-site scripting (XSS) in the changes dialog | GitLab Advisory Database (GLAD) CVE-2025-65012 Kirby CMS has cross-site scripting (XSS) in the changes dialog: The "Changes" dialog in the Panel displays all content models (pages, files,... https://funky-slipper-44f.notion.site/Privilege-Escalation-using-XSS-d98e8f4a738146e5bf6aefe4c51c33f7 Privilege Escalation using XSS | Notion CSRF Bypass in Rails Application: privilege escalationusingxssnotion https://www.meetup.com/owasp-wellington/events/239202702/ Developer's guide to preventing XSS, Mon, May 29, 2017, 6:00 PM | Meetup Fresh from OWASP NZ Day 2017 (https://www.owasp.org/index.php/OWASP_New_Zealand_Day_2017), we bring you this talk: Abstract An introductory talk on cross site... https://advisories.gitlab.com/composer/silverstripe/framework/CVE-2024-47605/ Silverstripe Framework has a XSS via insert media remote file oembed | GitLab Advisory Database... CVE-2024-47605 Silverstripe Framework has a XSS via insert media remote file oembed: When using the "insert media" functionality, the linked oEmbed JSON... https://advisories.gitlab.com/composer/phpoffice/phpexcel/CVE-2025-22131/ Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet |... CVE-2025-22131 Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet: The researcher discovered zero-day vulnerability... cross site scriptingxssvulnerabilityfunction https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2025-24410/ Magento Stored Cross-Site Scripting (XSS) Vulnerability | GitLab Advisory Database (GLAD) CVE-2025-24410 Magento Stored Cross-Site Scripting (XSS) Vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and... cross site scriptingmagentostored https://advisories.gitlab.com/golang/github.com/prometheus/prometheus/GHSA-fw8g-cg8f-9j28/ Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI... GHSA-fw8g-cg8f-9j28 Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display: In the Prometheus server's... https://advisories.gitlab.com/golang/github.com/apache/incubator-answer/CVE-2024-29217/ Apache Answer: XSS vulnerability when changing personal website | GitLab Advisory Database (GLAD) CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website: Improper Neutralization of Input During Web Page Generation ('Cross-site... apache answer https://advisories.gitlab.com/npm/@excalidraw/excalidraw/GHSA-39h7-pwv7-rc3x/ Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) | GitLab... GHSA-39h7-pwv7-rc3x Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering): @excalidraw/excalidraw@0.18.0 depends on a Mermaid... https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/CVE-2026-29191/ ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint | GitLab Advisory Database... CVE-2026-29191 ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint: A vulnerability was discovered in Zitadel's login V2 interface that allowed... https://advisories.gitlab.com/golang/github.com/mattermost/mattermost-server/CVE-2017-18879/ Mattermost Server is vulnerable to XSS through author_link field in Slack attachments | GitLab... CVE-2017-18879 Mattermost Server is vulnerable to XSS through author_link field in Slack attachments: An issue was discovered in Mattermost Server before... https://advisories.gitlab.com/pypi/label-studio/CVE-2026-22033/ Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile... CVE-2026-22033 Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field: A persistent stored... https://advisories.gitlab.com/npm/serve-lite/CVE-2022-25847/ Cross-site Scripting (XSS) in serve-lite | GitLab Advisory Database (GLAD) CVE-2022-25847 Cross-site Scripting (XSS) in serve-lite: All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it... cross site scriptingxss https://advisories.gitlab.com/composer/craftcms/cms/CVE-2026-31859/ CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization | GitLab Advisory... CVE-2026-31859 CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization: The fix for CVE-2025-35939 in craftcms/cms introduced a... https://advisories.gitlab.com/composer/getgrav/grav/CVE-2026-42841/ Grav CMS vulnerable to stored XSS via Markdown media attribute() action | GitLab Advisory Database... CVE-2026-42841 Grav CMS vulnerable to stored XSS via Markdown media attribute() action: An authenticated user with page editing permissions can inject an... https://github.com/secdec/xssmap GitHub - secdec/xssmap: Intelligent XSS detection tool that uses human techniques for looking for... Intelligent XSS detection tool that uses human techniques for looking for reflected cross-site scripting (XSS) vulnerabilities - secdec/xssmap https://knowledge.broadcom.com/external/article/165915/content-security-policy-csp-example-for.html Content Security Policy (CSP) example for XSS prevention content security policycspexamplexssprevention