Stored XSS is a vulnerability tracked across 6 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed December 10, 2025; most recent activity July 21, 2026.
Stored XSS (persistent cross-site scripting) is a vulnerability where attacker-supplied scripts are stored on a server (in databases, logs, or content assets) and later delivered to users, allowing the code to execute in their browsers. Its persistence makes it a high-impact vector for attackers targeting content-rich web apps such as CMSs, forums, and comment sections, enabling actions like session hijacking, credential theft, or defacement.
A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an…
Gogs, an open source self-hosted Git service, has two critical vulnerabilities prior to version 0.14.2. CVE-2026-26276 allows attackers to execute a DOM-Based XSS via malicious HTML/JavaScript in Milestone names, while…
Ivanti has issued security updates for a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) product. This flaw could allow remote, unauthenticated attackers to execute arbitrary JavaScript code,…
Eurostar has resolved security vulnerabilities in its AI chatbot after being notified by Pen Test Partners. The chatbot, which utilizes a large language model, was found to have issues that could affect customer…
Researchers at Pen Test Partners identified four vulnerabilities in Eurostar's AI chatbot, including risks of HTML injection and leaking system prompts. After reporting these issues through the company's vulnerability…
A stored cross-site scripting (XSS) vulnerability in the RustFS Console has been identified, allowing attackers to steal admin S3 credentials. This flaw poses a significant risk of full account takeovers for affected…