Articles tagged XSS
-
Vulnerability6 CVEs Across 6 Vendors (CVE-2026-86217)
A roundup of six low-severity, unrelated vulnerabilities disclosed in September 2026: information disclosure and XSS in several small PHP student/hobby projects, an out-of-bounds read in Valkey requiring cluster-mode plus attacker file access, and a disputed SSRF report in OpenAgents.
-
Vulnerability@appium/base-driver Cross-Site Scripting (CVE-2026-58191)
CVE-2026-58191 lets an attacker execute arbitrary JavaScript on an Appium server via unauthenticated, unescaped test routes mounted on every server by default.
-
VulnerabilityPowerkit Cross-Site Scripting (CVE-2026-2390)
CVE-2026-2390 is a stored cross-site scripting vulnerability in the Powerkit WordPress plugin, exploitable by Contributor-level users via a flawed regex-based HTML parser in the Lazy Load module.