CVE Database - Medium Severity

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

53860
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2026-47977

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47975

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47974

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47973

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47972

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47970

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47966

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47962

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47958

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47957

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47956

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47954

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47953

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47951

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47950

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47949

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47948

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47947

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47946

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47945

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47944

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47943

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47942

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47941

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47939

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47936

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47935

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47641

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper Input Validation
WAF: Medium

CVE-2026-47640

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47639

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47638

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47637

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47636

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-47634

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45502

MEDIUM
5.00 CVSS 3.1

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Server-Side Request Forgery (SSRF)
WAF: Medium

CVE-2026-45500

MEDIUM
6.10 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45483

MEDIUM
4.60 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45479

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45468

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45467

MEDIUM
4.60 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45465

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45464

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45462

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-45453

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-42599

MEDIUM
6.10 CVSS 3.1

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires. This issue has been patched in version 5.55.7.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-42573

MEDIUM
6.10 CVSS 3.1

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-34692

MEDIUM
5.40 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-33113

MEDIUM
6.10 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Cross-Site Scripting (XSS)
WAF: High

CVE-2026-28301

MEDIUM
4.80 CVSS 3.1

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.

Open Redirect
WAF: Medium

CVE-2026-11790

MEDIUM
4.90 CVSS 3.1

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.

Uncontrolled Resource Consumption
WAF: Medium
Page 3 of 1078 (53860 CVEs)