CVE-2025-9211
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated a
CVSS
6.7
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 18 ago 2026 · Última mod.: 31 ago 2026 · CWE-79
0.3%EPSS · 30 días0.3%
2026-08-192026-09-01
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-848039.0 CRÍ—
——0SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.4hCVE-2026-847934.8 MED—
——0Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.4hCVE-2026-847816.5 MED—
——0Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.4hCVE-2026-835626.5 MED—
——0Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.4hCVE-2026-817757.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.4hCVE-2026-817717.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.4h