CVE-2026-42506
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attac
CVSS
6.1
Medium
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: May 22, 2026 · Last modified: Jul 23, 2026 · CWE-79
0.2%EPSS · 30 days0.2%
2026-07-292026-08-26
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-782827.1 HIG4.4%
——1Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.2dCVE-2026-782647.1 HIG4.1%
——1Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.2dCVE-2026-782637.1 HIG4.1%
——1Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.2dCVE-2026-325567.1 HIG4.1%
——1Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.2dCVE-2026-715036.1 MED11.2%
——3Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted. An unauthenticated attacker can cause an authenticated administrator to open a crafted URL to execute arbitrary JavaScript in that session and create a persistent administrator account.3dCVE-2026-308648.9 HIG9.7%
——3Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.3d