CVE-2026-86483
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVSS
5.4
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 7, 2026 · Last modified: Sep 7, 2026 · CWE-79
Not enough EPSS history yet.
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-864913.5 LOW—
———In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads4hCVE-2026-864844.6 MED—
———In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS4hCVE-2026-86440——
———Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget.
The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or if its parsed hostname matched the configured MISP hostname. That logic failed to reject dangerous schemes and URL forms that browsers normalize differently from PHP's URL parsing.
As a result, values such as javascript: URLs or backslash-based authority forms could reach the generated anchor's href and execute script or navigate to an attacker-controlled origin when another user interacted with the widget. The upstream commit describes the issue as:
“javascript: and backslash URLs reached the href (stored XSS)”.
The fix routes widget URLs through a shared DashboardURLValidator, rejects dangerous schemes, raw backslashes, control characters, and unauthorized absolute origins, and validates the URL both in the widget handler and renderer.
Version affected: ≤2.5.458hCVE-2026-864317.2 HIG—
———league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written verbatim into the output where browsers parse it as a genuine event handler. The same prefix also defeats the allow_unsafe_links check, allowing javascript: URIs through href/src attributes even when allow_unsafe_links is false. Exploitation requires processing untrusted Markdown with the AttributesExtension enabled; the injected script executes when the rendered HTML is viewed. Fixed in 2.9.1.8hCVE-2026-64317.2 HIG—
———The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.8hCVE-2026-863013.5 LOW—
——0A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.9h