#Cross-Site Scripting
All CosmicBytez Labs articles tagged #Cross-Site Scripting, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-76718: HPE OneView Cross-Site Scripting Flaw Enables Session Hijacking
High-severity CVSS 8.2 XSS flaw in HPE OneView (versions before 11.40) enables remote session hijacking of admin consoles; patched in OneView 11.40.
- Security
CVE-2026-45143: Chamilo LMS Stored XSS Enables Student-to-Admin Takeover
Unsanitized private messages in Chamilo LMS let a low-privilege student fire stored XSS at an admin's inbox, no link click required.
- Security
CVE-2026-17037: Kirki WordPress Plugin Unauthenticated Stored XSS
Unauthenticated Stored XSS in the Kirki WordPress plugin (≤ 6.2.0) via the comment parameter lets attackers inject persistent scripts. CVSS 7.2.
- Security
CVE-2026-85061: MapLibre GL JS DOM Sanitizer Bypass Enables Stored XSS
A live-collection iteration bug in MapLibre GL JS's DOM.sanitize() lets attacker-supplied attribution strings smuggle an event handler past sanitization.
- Security
CVE-2026-40541: Cross-Site Scripting Flaw in Synology Chat Server Enables File Tampering
Synology Chat Server's unsanitized link-preview domain lets authenticated users read/write arbitrary DSM files and cause denial-of-service.
- Security
CVE-2026-10087: GitLab EE Stored XSS via Developer Role
GitLab EE versions 17.1 through 19.x are affected by a stored cross-site scripting vulnerability (CVSS 8.7) that allows an authenticated developer to...
- Security
CVE-2026-42849: authentik Critical XSS in AutosubmitStage (CVSS 9.3)
A critical cross-site scripting vulnerability in authentik's Simple Flow Executor AutosubmitStage allows attackers to execute arbitrary JavaScript via a…
- Security
CVE-2025-61311: Reflected XSS in docuForm Managed Print
A reflected cross-site scripting vulnerability in the dfm-menu_alerts.php component of GmbH Mecury docuForm v11.11c allows attackers to execute arbitrary...
- Security
CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin
A stored cross-site scripting vulnerability in RealtyScript 4.0.2 allows attackers to inject malicious JavaScript via the location_name parameter in the...