CWE-87: Improper Neutralization of Alternate XSS Syntax
The product does not neutralize or incorrectly neutralizes user-controlled input for alternate script syntax.
54 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-33506 — DOM-Based XSS in Ory Polis Login Page
- CVE-2025-49137 — Hax CMS Stored Cross-Site Scripting vulnerability
- CVE-2025-54369 — Node-SAML SAML Authentication Bypass
- CVE-2026-55237 — AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
- CVE-2026-42235 — n8n: XSS via MCP OAuth client
- CVE-2026-33510 — DOM-Based XSS in Homarr /auth/login Redirect
- CVE-2026-34598 — YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
- CVE-2025-55291 — Shaarli allows reflected XSS via searchtags parameter
- CVE-2026-54002 — Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
- CVE-2025-62418 — bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (SVG)
- CVE-2025-62415 — bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (HTML)
- CVE-2025-62414 — bagisto - Cross Site Scripting (XSS) in Create New Customer
- CVE-2025-48366 — GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
- CVE-2026-40321 — DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
- CVE-2026-35534 — ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection
- CVE-2026-45314 — Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-46492 — md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-22711 — Stored XSS through system messages in WikiLove
- CVE-2024-4459 — Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles
- CVE-2025-14732 — Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
Recently published
- CVE-2026-79946 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-54002 — Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
- CVE-2026-55661 — TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
- CVE-2026-55237 — AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
- CVE-2026-46492 — md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-25688 — Apache Answer: XSS in AI Answer Rendering
- CVE-2026-45314 — Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-42458 — Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
- CVE-2026-42235 — n8n: XSS via MCP OAuth client
- CVE-2026-40321 — DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
- CVE-2025-14732 — Elementor Website Builder <= 3.35.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API
- CVE-2026-22711 — Stored XSS through system messages in WikiLove
- CVE-2026-35534 — ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection
- CVE-2026-33510 — DOM-Based XSS in Homarr /auth/login Redirect
- CVE-2026-34598 — YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
- CVE-2026-33506 — DOM-Based XSS in Ory Polis Login Page
- CVE-2025-52563 — Chamilo: Reflected XSS via page parameter
- CVE-2025-54369 — Node-SAML SAML Authentication Bypass
- CVE-2025-65961 — Contao is vulnerable to cross-site scripting in templates
- CVE-2025-48076 — Galette is vulnerable to Cross-site Scripting