CVE-2026-15394
The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVSS
6.4
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-79
Sin historial EPSS suficiente todavía.
The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-admin.php#L400
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php#L145
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php#L253
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?reponame=&old=3611085%40header-and-footer-script-adder&new=3611085%40header-and-footer-script-adder
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/c394c9bc-21f6-45ea-8eda-8ee22a9b87ba?source=cve
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-656069.6 CRÍ—
——0SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.5hCVE-2026-656059.6 CRÍ—
——0SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution.5hCVE-2026-655505.9 MED—
——0Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.5hCVE-2026-655385.9 MED—
——0Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.5hCVE-2026-655345.9 MED—
——0Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.5hCVE-2026-655336.5 MED—
——0Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.5h