CVE-2026-59513
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-79
Sin historial EPSS suficiente todavía.
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-656069.6 CRÍ—
——0SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.6hCVE-2026-656059.6 CRÍ—
——0SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution.6hCVE-2026-655505.9 MED—
——0Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.6hCVE-2026-655385.9 MED—
——0Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.6hCVE-2026-655345.9 MED—
——0Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.6hCVE-2026-655336.5 MED—
——0Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.6h