Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetEngine allows DOM-Based XSS. This issue affects JetEngine: from n/a through 3.6.4.1.
Publication date: Tue, 15 Apr 2025 21:53:00 +0000
Cyber News related to CVE-2025-26870
CVE-2025-26870 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetEngine allows DOM-Based XSS. This issue affects JetEngine: from n/a through 3.6.4.1. ...
8 months ago
CVE-2021-38193 - An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. ...
4 years ago
CVE-2020-27176 - Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, ...
5 years ago
CVE-2020-26870 - Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. ...
3 years ago
CVE-2021-26870 - Windows Projected File System Elevation of Privilege Vulnerability ...
3 years ago
CVE-2022-26870 - Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful ...
3 years ago
CVE-2024-26870 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago