Known Vulnerabilities for Browsers by Microsoft Corporation
Listed below are 10 of the newest known vulnerabilities associated with "Browsers" by "Microsoft Corporation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64795 json | Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A c... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-61453 json | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss(... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-60120 json | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unau... | Not Provided | 2026-07-09 | 2026-07-14 |
| CVE-2026-59802 json | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url fun... | Not Provided | 2026-07-08 | 2026-07-14 |
| CVE-2026-59102 json | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arb... | Not Provided | 2026-07-02 | 2026-07-06 |
| CVE-2026-58475 json | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-58228 json | Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation a... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-57958 json | Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execut... | Not Provided | 2026-06-29 | 2026-06-29 |
| CVE-2026-56785 json | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-54889 json | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting... | Not Provided | 2026-06-29 | 2026-06-30 |