Stored XSS - Vulnerability

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
December 10, 2025
Last Seen
July 21, 2026

Stored XSS is a vulnerability tracked across 6 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed December 10, 2025; most recent activity July 21, 2026.

Overview

Stored XSS (persistent cross-site scripting) is a vulnerability where attacker-supplied scripts are stored on a server (in databases, logs, or content assets) and later delivered to users, allowing the code to execute in their browsers. Its persistence makes it a high-impact vector for attackers targeting content-rich web apps such as CMSs, forums, and comment sections, enabling actions like session hijacking, credential theft, or defacement.

Related Threat Clusters

Recent Intelligence Reports

  • Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover ThreatCluster - Threat Intelligence Feed / 24min Key Points: • CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS. • The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3. — threatcluster.io · July 21, 2026
  • CVE-2026-16155: XSS (CVSS 3.5) — Secably · July 19, 2026
  • CVE-2026-26195 — Nvd.Nist · March 6, 2026
  • Stored XSS Flaw in RustFS Console Leaks Admin S3 Credentials — Cyberpress · February 28, 2026
  • Eurostar AI vulnerability: when a chatbot goes off the rails — News.Ycombinator · January 4, 2026
  • Pen testers accused of 'blackmail' after reporting Eurostar chatbot flaws — Theregister · December 24, 2025
  • CC-4726 — Digital.Nhs.Uk · December 10, 2025

CVSS v3.1 Breakdown