Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
36 articles

#XSS

All CosmicBytez Labs articles tagged #XSS, across news, security advisories, how-to guides, and projects.

  • SecurityAug 28, 2026

    CVE-2026-59354: Spring Security OAuth2 Authorization Server Dynamic Client Registration Flaw

    Critical flaw (CVSS 9.6) in Spring Security Authorization Server 7.0.0-7.0.4 lets a registered client trigger stored XSS, SSRF, or privilege escalation.

  • SecurityAug 24, 2026

    CVE-2026-7808: justhtml HTML Sanitization Bypass (Critical XSS)

    Critical XSS in justhtml before 1.16.0. Multiple bypass paths let dangerous content survive sanitization, enabling script injection with no auth required.

  • SecurityAug 24, 2026

    CVE-2026-8445: justhtml Markdown Conversion XSS via Unescaped Angle Brackets

    Critical XSS in justhtml <=1.11.0. The to_markdown() function leaves angle brackets unescaped, allowing raw HTML to reach downstream Markdown renderers.

  • SecurityAug 23, 2026

    CVE-2026-5388: Critical XSS Sanitization Bypass in justhtml

    justhtml before 1.15.0 has multiple sanitization failures allowing XSS bypass via URL helpers, HTML serialization, and Markdown passthrough.

  • SecurityAug 19, 2026

    CVE-2026-75626: SpiderFoot Stored XSS via Unsanitized Correlation Titles

    SpiderFoot fails to HTML-escape correlation titles from external scan data, enabling stored XSS attacks that execute scripts in the operator's browser.

  • SecurityAug 18, 2026

    CVE-2026-74800: SiYuan Stored XSS via Asset Upload Enables Full Kernel API Access

    SiYuan before 3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers, enabling stored XSS with full kernel API access.

  • SecurityAug 16, 2026

    CVE-2026-73041: SiYuan XSS via PDF Annotation Fields Grants Full Node.js Access

    Critical CVSS 9.0 XSS in SiYuan's PDF annotation renderer allows script injection with full Node.js access on affected versions before v3.7.4.

  • SecurityAug 16, 2026

    SiYuan Stored XSS via Database Menu Metadata (CVE-2026-73042)

    SiYuan before v3.7.4 fails to escape database menu metadata, enabling stored XSS in group, view, and field-edit menus. CVSS 9.0 Critical.

  • SecurityAug 16, 2026

    SiYuan Column Width API Stored XSS (CVE-2026-73044)

    SiYuan before v3.7.4 allows stored XSS via unescaped table column width values in style attributes. CVSS 9.0 Critical. Patch to v3.7.4.

  • SecurityAug 16, 2026

    SiYuan Stored XSS via Select Option Color Field (CVE-2026-73050)

    SiYuan before v3.7.4 fails to escape the color field in attribute-view select options, enabling stored XSS at eight render sites. CVSS 9.0.

  • SecurityAug 14, 2026

    CVE-2026-28154: Reflected XSS in WooCommerce WordPress Themes

    High-severity reflected XSS in Samex and M.Anh WooCommerce themes allows attackers to inject malicious scripts via crafted URLs.

  • SecurityJul 31, 2026

    CVE-2026-11707: IBM WebSphere Application Server Admin Console XSS (CVSS 9.3)

    Critical cross-site scripting vulnerability in IBM WebSphere Application Server's administrative console login page enables unauthenticated remote attackers to hijack admin sessions.

  • NewsJul 23, 2026

    Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client —...

  • SecurityJul 22, 2026

    CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

    A CVSS 9.3 critical stored XSS vulnerability in the Ninja Forms WordPress plugin affects versions 3.10.4 through 3.14.9. The flaw requires no...

  • SecurityJul 20, 2026

    CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

    A stored cross-site scripting vulnerability in the Unlimited Elements for Elementor WordPress plugin (before 2.0.11) allows unauthenticated attackers to...

  • NewsJul 11, 2026

    Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

    A critical stored XSS vulnerability in Zimbra's Classic Web Client allows attackers to deliver specially crafted emails that execute arbitrary code within...

  • SecurityJul 11, 2026

    CVE-2026-55879: OpenReplay Stored XSS Enables Dashboard Account Takeover

    A critical stored XSS vulnerability in OpenReplay's session replay SDK allows unauthenticated attackers to inject malicious scripts via the public...

  • NewsJul 10, 2026

    Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

    CVE-2025-27915, a stored XSS vulnerability in Zimbra's Classic Web Client, was exploited as a zero-day before public disclosure. Attackers used malicious...

  • SecurityJul 10, 2026

    CVE-2026-2342: ValeApp Stored Cross-Site Scripting (CVSS 9.3)

    A critical stored XSS vulnerability in OceanicSoft's ValeApp allows attackers to inject persistent JavaScript payloads that execute in every victim's...

  • SecurityJun 16, 2026

    CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

    WordPress CP Polls plugin version 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through...

  • SecurityJun 14, 2026

    CVE-2026-5513: Bookly WordPress Plugin Stored XSS via Cookie

    The Bookly scheduling plugin for WordPress contains a stored cross-site scripting vulnerability in versions up to 27.2, allowing unauthenticated attackers...

  • SecurityJun 13, 2026

    CVE-2026-44990: sanitize-html XMP Element XSS Bypass (CVSS 9.3)

    sanitize-html versions prior to 2.17.4 allow attacker-controlled content inside a disallowed xmp element to render as live HTML, enabling stored XSS.

  • SecurityJun 12, 2026

    CVE-2026-10087: GitLab EE Stored XSS via Developer Role

    GitLab EE versions 17.1 through 19.x are affected by a stored cross-site scripting vulnerability (CVSS 8.7) that allows an authenticated developer to...

  • SecurityJun 4, 2026

    CVE-2026-36748: High-Severity Stored XSS in RockRMS via Social Media Profile Links

    RockRMS versions up to v16.13 are vulnerable to a CVSS 9.0 stored cross-site scripting flaw that allows attackers to inject malicious scripts through social…

  • SecurityJun 3, 2026

    CVE-2026-42849: authentik Critical XSS in AutosubmitStage (CVSS 9.3)

    A critical cross-site scripting vulnerability in authentik's Simple Flow Executor AutosubmitStage allows attackers to execute arbitrary JavaScript via a…

  • NewsMay 18, 2026

    Microsoft Exchange Zero-Day Under Attack, No Patch Available

    A zero-day XSS vulnerability in Microsoft Exchange Server (CVE-2026-42897) is being actively exploited in the wild, allowing attackers to compromise...

  • SecurityMay 15, 2026

    CVE-2026-44212: PrestaShop Stored XSS in Customer Service

    A stored Cross-Site Scripting vulnerability (CVSS 9.3) in PrestaShop's back-office Customer Service view allows unauthenticated attackers to inject...

  • SecurityMay 12, 2026

    CVE-2025-61311: Reflected XSS in docuForm Managed Print

    A reflected cross-site scripting vulnerability in the dfm-menu_alerts.php component of GmbH Mecury docuForm v11.11c allows attackers to execute arbitrary...

  • SecurityMay 3, 2026

    CVE-2026-5324: WordPress Brizy Page Builder Unauthenticated

    The Brizy Page Builder plugin for WordPress contains a critical unauthenticated Stored Cross-Site Scripting flaw in versions up to 2.8.11, enabling...

  • NewsApr 26, 2026

    Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

    CISA has confirmed that a cross-site scripting vulnerability in Zimbra Collaboration Suite is being actively exploited in the wild, with over 10,000...

  • SecurityApr 24, 2026

    Hackage Haskell Repository Stored XSS Enables Credential

    A critical stored XSS vulnerability in hackage-server allows HTML and JavaScript files uploaded via source packages or documentation to execute in...

  • SecurityApr 17, 2026

    CVE-2026-40322: SiYuan XSS via Mermaid innerHTML Injection

    SiYuan knowledge management versions 3.6.3 and below render Mermaid diagrams with loose security, allowing attacker-controlled javascript: URLs to execute...

  • SecurityApr 11, 2026

    CVE-2026-31845: Rukovoditel CRM Reflected XSS in Zadarma

    Rukovoditel CRM versions 3.6.4 and earlier contain a critical reflected XSS vulnerability in the Zadarma telephony API endpoint. The application reflects...

  • SecurityMar 17, 2026

    CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin

    A stored cross-site scripting vulnerability in RealtyScript 4.0.2 allows attackers to inject malicious JavaScript via the location_name parameter in the...

  • SecurityMar 16, 2026

    CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File

    CVE-2015-20115 is a stored cross-site scripting vulnerability in RealtyScript 4.0.2 that allows authenticated attackers to upload malicious script files...

  • SecurityMar 8, 2026

    ZITADEL Critical XSS in SAML Endpoint Enables 1-Click

    A critical cross-site scripting vulnerability in ZITADEL's login V2 /saml-post endpoint allows unauthenticated attackers to execute arbitrary JavaScript...