CVE-2026-105061 — Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
Cybersecurity watch: alerts, vulnerabilities, news and tools to protect yourself.
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gat…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all v…
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross s…
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attac…
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node componen…