Known Vulnerabilities for Encoding/xml by Go Standard Library
Listed below are 10 of the newest known vulnerabilities associated with "Encoding/xml" by "Go Standard Library".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73628 json | Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL rou... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73418 json | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the expo... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73051 json | actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts request... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-72912 json | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe p... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-72787 json | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names a... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-72748 json | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72553 json | A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent Jav... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-71475 json | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into ... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-71446 json | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded dir... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-71445 json | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred ... | Not Provided | 2026-08-06 | 2026-08-07 |