5.1

CVSS4.0

CVE-2026-24907 - October CMS has Stored XSS via Event Log Mail Preview

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged mail messages, HTML content was rendered in an iframe without proper sandboxing, al…

πŸ“… Published: April 14, 2026, 5:34 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.6

CVSS3.1

CVE-2026-27303 - Adobe Connect | Deserialization of Untrusted Data (CWE-502)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 15, 2026, 3:58 a.m.

8.7

CVSS3.1

CVE-2026-34617 - Adobe Connect | Cross-site Scripting (XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or contr…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 7:10 p.m.

6.1

CVSS3.1

CVE-2026-21331 - Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. S…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 6:33 p.m.

9.3

CVSS3.1

CVE-2026-27246 - Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requ…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 6:16 p.m.

6.1

CVSS3.1

CVE-2026-34614 - Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. S…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 7:18 p.m.

9.3

CVSS3.1

CVE-2026-27245 - Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. S…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 7:27 p.m.

9.3

CVSS3.1

CVE-2026-34615 - Adobe Connect | Deserialization of Untrusted Data (CWE-502)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 15, 2026, 3:58 a.m.

9.3

CVSS3.1

CVE-2026-27243 - Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. S…

πŸ“… Published: April 14, 2026, 5:33 p.m. πŸ”„ Last Modified: April 14, 2026, 7:10 p.m.

5.1

CVSS4.0

CVE-2026-24906 - October CMS has Stored XSS in its Backend Editor Markup Classes

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline styles, table styles, etc.) did not sanitize inpu…

πŸ“… Published: April 14, 2026, 5:23 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345149
Page 63 of 34,515
Β« previous page Β» next page
Filters