<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Stored-Xss — PoC Archive</title><link>https://poc.intelseclab.com/tags/stored-xss/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/stored-xss/index.xml" rel="self" type="application/rss+xml"/><item><title>WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-40791. Status: PoC. Affects: WP Time Slots Booking Form (wp-time-slots-booking-form WordPress plugin). Tags: wordpress, wordpress-plugin, stored-xss, unauthenticated, cwe-79, admin-takeover, booking-form.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>stored-xss</category><category>unauthenticated</category><category>cwe-79</category><category>admin-takeover</category><category>booking-form</category></item><item><title>VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</guid><description>High severity (CVSS 8.5) — web · CVE-2026-5615. Status: PoC. Affects: VvvebJs (drag-and-drop website builder). Tags: vvvebjs, stored-xss, svg-upload, file-upload, cms.</description><category>web</category><category>High</category><category>vvvebjs</category><category>stored-xss</category><category>svg-upload</category><category>file-upload</category><category>cms</category></item><item><title>TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</guid><description>Medium severity — web · CVE-2026-27621 (GHSA-xfvg-8v67-j7wp). Status: PoC. Affects: TypiCMS Core (typicms/core). Tags: typicms, stored-xss, svg-upload, cwe-79, cms, file-upload, laravel, session-hijack.</description><category>web</category><category>Medium</category><category>typicms</category><category>stored-xss</category><category>svg-upload</category><category>cwe-79</category><category>cms</category><category>file-upload</category><category>laravel</category><category>session-hijack</category></item><item><title>Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</guid><description>High severity — web · CVE-2026-22804 (GHSA-m3cv-5hgp-hv35). Status: Weaponized. Affects: Termix (Electron-based SSH/terminal manager), File Manager component (FileViewer.tsx). Tags: termix, electron, stored-xss, svg-injection, session-hijacking, lfi, file-manager, ssh.</description><category>web</category><category>High</category><category>termix</category><category>electron</category><category>stored-xss</category><category>svg-injection</category><category>session-hijacking</category><category>lfi</category><category>file-manager</category><category>ssh</category></item><item><title>Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23499-saleor-file-upload-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23499-saleor-file-upload-xss/</guid><description>High severity — web · CVE-2026-23499. Status: PoC. Affects: Saleor (saleor/saleor). Tags: saleor, stored-xss, unrestricted-file-upload, svg-xss, session-hijack, graphql, javascript.</description><category>web</category><category>High</category><category>saleor</category><category>stored-xss</category><category>unrestricted-file-upload</category><category>svg-xss</category><category>session-hijack</category><category>graphql</category><category>javascript</category></item><item><title>Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22849-saleor-richtext-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22849-saleor-richtext-stored-xss/</guid><description>High severity — web · CVE-2026-22849 (GHSA-8jcj-r5g2-qrpv). Status: PoC. Affects: Saleor (open-source e-commerce platform), rich text fields (EditorJS content on pages/products). Tags: saleor, stored-xss, editorjs, graphql, ecommerce, session-hijacking, cwe-79.</description><category>web</category><category>High</category><category>saleor</category><category>stored-xss</category><category>editorjs</category><category>graphql</category><category>ecommerce</category><category>session-hijacking</category><category>cwe-79</category></item><item><title>Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-40487 / GHSA-44wg-r34q-hvfx. Status: PoC. Affects: Postiz (open-source social media management platform, gitroomhq/postiz-app). Tags: file-upload, mime-spoofing, stored-xss, account-takeover, postiz, nodejs, oauth-backdoor.</description><category>web</category><category>High</category><category>file-upload</category><category>mime-spoofing</category><category>stored-xss</category><category>account-takeover</category><category>postiz</category><category>nodejs</category><category>oauth-backdoor</category></item><item><title>oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</guid><description>High severity — web · CVE-2026-33331 (GHSA-7f6v-3gx7-27q8). Status: PoC. Affects: middleapi/orpc — OpenAPI documentation reference plugin (packages/openapi/src/plugins/openapi-reference.ts). Tags: xss, stored-xss, orpc, openapi, cwe-79, javascript, nodejs, docs-page.</description><category>web</category><category>High</category><category>xss</category><category>stored-xss</category><category>orpc</category><category>openapi</category><category>cwe-79</category><category>javascript</category><category>nodejs</category><category>docs-page</category></item><item><title>NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-3228. Status: PoC. Affects: NextScripts: Social Networks Auto-Poster (WordPress plugin). Tags: wordpress, xss, stored-xss, plugin, contributor-privilege, shortcode, session-hijacking.</description><category>web</category><category>Medium</category><category>wordpress</category><category>xss</category><category>stored-xss</category><category>plugin</category><category>contributor-privilege</category><category>shortcode</category><category>session-hijacking</category></item><item><title>Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35455-immich-exfiltration/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35455-immich-exfiltration/</guid><description>High severity — web · CVE-2026-35455. Status: Weaponized. Affects: Immich (self-hosted photo/video management). Tags: immich, stored-xss, exfiltration, api-key-theft, account-hijacking, self-hosted-photos, c2.</description><category>web</category><category>High</category><category>immich</category><category>stored-xss</category><category>exfiltration</category><category>api-key-theft</category><category>account-hijacking</category><category>self-hosted-photos</category><category>c2</category></item><item><title>EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33657-espocrm-stored-html-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33657-espocrm-stored-html-injection/</guid><description>Medium severity — web · CVE-2026-33657. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, html-injection, stored-xss, cwe-80, email-notifications, authenticated, crm, template-injection.</description><category>web</category><category>Medium</category><category>espocrm</category><category>html-injection</category><category>stored-xss</category><category>cwe-80</category><category>email-notifications</category><category>authenticated</category><category>crm</category><category>template-injection</category></item><item><title>ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-2600. Status: Weaponized. Affects: ElementsKit Elementor Addons (WordPress plugin). Tags: wordpress, elementor, stored-xss, rest-api, privilege-escalation, contributor, plugin, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>elementor</category><category>stored-xss</category><category>rest-api</category><category>privilege-escalation</category><category>contributor</category><category>plugin</category><category>cwe-79</category></item><item><title>Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5513-bookly-cookie-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5513-bookly-cookie-stored-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-5513. Status: PoC. Affects: Bookly — Online Scheduling and Appointment Booking System (WordPress plugin). Tags: wordpress, bookly, stored-xss, cwe-79, cookie-injection, appointment-booking.</description><category>web</category><category>High</category><category>wordpress</category><category>bookly</category><category>stored-xss</category><category>cwe-79</category><category>cookie-injection</category><category>appointment-booking</category></item><item><title>BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41653-bentopdf-stored-xss-exfil/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41653-bentopdf-stored-xss-exfil/</guid><description>Critical severity — web · CVE-2026-41653. Status: PoC. Affects: BentoPDF (self-hosted browser-side PDF toolbox). Tags: xss, stored-xss, file-exfiltration, client-side, service-worker, wasm-hijack, pdf-toolbox, markdown-injection.</description><category>web</category><category>Critical</category><category>xss</category><category>stored-xss</category><category>file-exfiltration</category><category>client-side</category><category>service-worker</category><category>wasm-hijack</category><category>pdf-toolbox</category><category>markdown-injection</category></item><item><title>Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30862-appsmith-stored-xss-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30862-appsmith-stored-xss-privesc/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-30862 (GHSA-5hw4-whxv-6794). Status: PoC. Affects: Appsmith. Tags: appsmith, stored-xss, csrf, privilege-escalation, xsrf-token, react, low-code.</description><category>web</category><category>Critical</category><category>appsmith</category><category>stored-xss</category><category>csrf</category><category>privilege-escalation</category><category>xsrf-token</category><category>react</category><category>low-code</category></item></channel></rss>