CVE-2026-15662
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVSS
6.4
Medium
EPSS
0.2%
p13
KEV
—
Exploit Today
4
0-100
Published: Aug 1, 2026 · Last modified: Aug 12, 2026 · CWE-79
0.2%EPSS · 30 days0.2%
2026-08-012026-08-30
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/advanced-woo-labels.php#L231
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/admin/class-awl-admin.php#L123
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/awl-functions.php#L93
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L332
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L434
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L449
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L560
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?reponame=&old=3627180%40advanced-woo-labels&new=3627180%40advanced-woo-labels
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/50eef578-9094-47ac-a451-04ebd9e6e2f8?source=cve
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-826548.9 HIG—
——0SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.7hCVE-2026-826538.9 HIG—
——0SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.7hCVE-2026-826466.1 MED—
——0WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a legitimate-looking link on the site's own domain to execute JavaScript in victims' sessions and steal cookies or CSRF tokens.7hCVE-2026-826428.8 HIG—
——0Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPurify does not parse the contents of the srcdoc attribute on <iframe> elements, treating it as an opaque string attribute, so an attacker who can get an <iframe> element to survive sanitization can embed a complete HTML document containing a <script> tag inside srcdoc and have it execute when the browser renders the iframe. The content iframe is configured with sandbox="allow-same-origin allow-scripts", so script executing inside it shares the parent origin and can reach parent.parent.__TAURI_INTERNALS__.invoke(...), giving access to every Tauri IPC command the application is permitted to use, which escalates to arbitrary code execution. The payload can be made invisible (zero-size, transparent iframe) so the reader sees only normal book text. Version 0.11.16 hardened the sanitizer configuration by adding 'iframe', 'object' and 'embed' to FORBID_TAGS and adding 'srcdoc' to FORBID_ATTR.8hCVE-2026-824883.5 LOW—
——0A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.11hCVE-2026-824833.5 LOW9.7%
——3A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.14h