CVE-2026-81775
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
CVSS
7.1
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 2, 2026 · Last modified: Sep 2, 2026 · CWE-79
Not enough EPSS history yet.
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-848039.0 CRI—
——0SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.3hCVE-2026-847934.8 MED—
——0Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.3hCVE-2026-847816.5 MED—
——0Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.3hCVE-2026-835626.5 MED—
——0Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.3hCVE-2026-817717.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.3hCVE-2026-817707.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.3h