CVE Database - Cross-Site Scripting (XSS)

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

44693
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2026-47978

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47977

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47975

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47974

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47973

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47972

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47970

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47966

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47962

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47958

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47957

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47956

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47954

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47953

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47951

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47950

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47949

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47948

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47947

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47946

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47945

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47944

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47943

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47942

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47941

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47939

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47936

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47935

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47640

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47639

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47638

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47637

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47636

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47634

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47631

HIGH
8.10 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45644

HIGH
8.00 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45500

MEDIUM
6.10 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45483

MEDIUM
4.60 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45481

HIGH
7.30 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45479

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45468

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45467

MEDIUM
4.60 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45465

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45464

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45462

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45453

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-42599

MEDIUM
6.10 CVSS 3.1

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires. This issue has been patched in version 5.55.7.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-42573

MEDIUM
6.10 CVSS 3.1

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-41098

HIGH
8.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-34692

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High
Page 3 of 894 (44693 CVEs)