CVE-2026-62138
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- CWE
- CWE-79
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Visual Composer Visual Composer Website Builder
Weakness type
Related vulnerabilities
- CVE-2026-89268 — QloApps through 1.7.0 Reflected XSS via List Filter Parameters
- CVE-2026-90443 — A web interface reflects a portion of the request URL into a script context and a hyperlink...
- CVE-2026-54165 — Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)
- CVE-2026-81918 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
- CVE-2026-81917 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
- CVE-2026-77490 — Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-81911 — Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description
- CVE-2026-62111 — WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability