Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Openemr MEDIUM 5.4
CVE-2026-32125

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the …

Fix: 8.0.0.1+
Fix from $1,600 2026-03-11
Openemr CRITICAL 9.0
CVE-2026-32118

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scriptin…

Fix: 8.0.0.1+
Fix from $2,300 2026-03-11
Openemr MEDIUM 5.4
CVE-2026-32121

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescriptio…

Fix: 8.0.0.1+
Fix from $1,600 2026-03-11
Plunk MEDIUM 5.4
CVE-2026-32095

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers trea…

Fix: 0.7.1+
Fix from $1,600 2026-03-11
Notesnook Desktop MEDIUM 5.4
CVE-2026-31876

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in No…

Fix: 3.3.9 / 3.3.15+
Fix from $1,600 2026-03-11
Frappe MEDIUM 5.4
CVE-2026-31879

Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission check…

Fix: 14.100.2 / 15.101.0+
Fix from $1,600 2026-03-11
Parse Server MEDIUM 6.1
CVE-2026-31868

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacke…

Fix: 8.6.30 / 9.6.0+
Fix from $1,600 2026-03-11
Craft Cms MEDIUM 6.1
CVE-2026-31859

Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize…

Fix: 4.17.3 / 5.9.7+
Fix from $1,600 2026-03-11
Openproject MEDIUM 6.5
CVE-2026-30235

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenPr…

Fix: 17.2.0+
Fix from $1,600 2026-03-11
Splunk MEDIUM 6.3
CVE-2026-20162

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510.4, 10.1.2507.15, 10.0.2503.1…

Fix: 9.3.9 / 9.3.2411.123+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.1
CVE-2026-20116

A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified …

Mitigation only
Fix from $1,600 2026-03-11
Unified Contact Center Express MEDIUM 6.1
CVE-2026-20117

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote at…

Fix: after 15.0
Fix from $1,600 2026-03-11
GitLab MEDIUM 5.4
CVE-2026-1090

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could …

Fix: 18.7.6 / 18.8.6+
Fix from $1,600 2026-03-11
Unclassified HIGH 7.2
CVE-2026-3178

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, a…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-3492

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a …

Mitigation only
Fix from $1,600 2026-03-11
Unclassified HIGH 7.2
CVE-2026-3231

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and c…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified HIGH 7.2
CVE-2026-1454

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,…

Mitigation only
Fix from $1,950 2026-03-11
Organization Portal System MEDIUM 6.1
CVE-2026-3825

IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaSc…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-3534

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post …

Mitigation only
Fix from $1,600 2026-03-11
Spin.js MEDIUM 6.1
CVE-2026-3884

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than…

Fix: 3.0.0+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-2358

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all …

Patch available
Fix from $1,600 2026-03-11
Unclassified HIGH 7.1
CVE-2026-2466

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected C…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-2707

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and i…

Patch available
Fix from $1,600 2026-03-11
Commerce HIGH 8.1
CVE-2026-21361

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Commerce HIGH 8.0
CVE-2026-21311

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Commerce B2b MEDIUM 5.4
CVE-2026-21292

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Commerce B2b HIGH 8.1
CVE-2026-21284

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Commerce B2b HIGH 8.7
CVE-2026-21290

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-03-11
Unclassified MEDIUM 6.1
CVE-2025-12473

The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all versions up to, and including…

Mitigation only
Fix from $1,600 2026-03-11
Experience Manager MEDIUM 5.4
CVE-2026-27262

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att…

Fix: 6.5.24.0 / 2026.2.0+
Fix from $1,600 2026-03-11