Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Experience Manager MEDIUM 5.4
CVE-2026-27225

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-…

Fix: 6.5.24.0 / 2026.2.0+
Fix from $1,600 2026-03-11
Experience Manager MEDIUM 5.4
CVE-2026-27226

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att…

Fix: 6.5.24.0 / 2026.2.0+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.4
CVE-2026-2569

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PDF page l…

Mitigation only
Fix from $1,600 2026-03-11
Umbraco Cms MEDIUM 6.7
CVE-2026-31833

Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTM…

Fix: 16.5.1 / 17.2.2+
Fix from $1,600 2026-03-10
Sylius MEDIUM 6.1
CVE-2026-31822

Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by…

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Siyuan MEDIUM 6.1
CVE-2026-31807

SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous elements (<script>, <iframe>…

Fix: 3.5.10+
Fix from $1,600 2026-03-10
Siyuan MEDIUM 6.1
CVE-2026-31809

SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: pr…

Fix: 3.5.10+
Fix from $1,600 2026-03-10
Parse Server MEDIUM 5.4
CVE-2026-30948

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored c…

Fix: 8.6.17 / 9.5.2+
Fix from $1,600 2026-03-10
Enterprise Server MEDIUM 5.4
CVE-2026-2266

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task lis…

Fix: 3.18.6 / 3.19.3+
Fix from $1,600 2026-03-10
Craft Commerce MEDIUM 5.4
CVE-2026-29177

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Cra…

Fix: 4.10.2 / 5.5.3+
Fix from $1,600 2026-03-10
Craft Commerce MEDIUM 5.4
CVE-2026-29175

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product T…

Fix: 5.5.3+
Fix from $1,600 2026-03-10
Pluxml MEDIUM 6.1
CVE-2025-70128

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The applicati…

Fix: after 5.8.22
Fix from $1,600 2026-03-10
Aspera Faspex MEDIUM 5.4
CVE-2025-36226

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Fix: 5.0.15+
Fix from $1,600 2026-03-10
Unclassified MEDIUM 6.4
CVE-2026-3228

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in a…

Mitigation only
Fix from $1,600 2026-03-10
Copyparty MEDIUM 5.4
CVE-2026-30974

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML …

Fix: 1.20.11+
Fix from $1,600 2026-03-10
Filebrowser MEDIUM 5.4
CVE-2026-30934

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata f…

Fix: after 1.2.9
Fix from $1,600 2026-03-10
Unclassified HIGH 7.2
CVE-2026-2724

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up t…

Mitigation only
Fix from $1,950 2026-03-10
Fortisiem MEDIUM 6.1
CVE-2026-25972

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 th…

Fix: 7.3.5+
Fix from $1,600 2026-03-10
Sharepoint Server CRITICAL 9.3
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20076+
Fix from $2,300 2026-03-10
Unclassified HIGH 7.2
CVE-2026-1261

The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 du…

Mitigation only
Fix from $1,950 2026-03-10
Generatedata MEDIUM 6.1
CVE-2025-70025

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen generatedata 4.0.14.

Mitigation only
Fix from $1,600 2026-03-10
Modicon M258 Firmware MEDIUM 5.4
CVE-2025-13902

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where aut…

Fix: 5.4.13.12+
Fix from $1,600 2026-03-10
Unclassified HIGH 8.8
CVE-2026-30917

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table…

Patch available
Fix from $1,950 2026-03-10
Facilemanager MEDIUM 6.1
CVE-2026-30918

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives da…

Fix: 6.0.4+
Fix from $1,600 2026-03-10
Facilemanager MEDIUM 5.4
CVE-2026-30919

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order X…

Fix: 6.0.4+
Fix from $1,600 2026-03-10
Appsmith CRITICAL 9.0
CVE-2026-30862

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table …

Fix: 1.96+
Fix from $2,300 2026-03-10
Unclassified MEDIUM 6.1
CVE-2026-0489

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated atta…

Mitigation only
Fix from $1,600 2026-03-10
Infosphere Data Architect MEDIUM 6.1
CVE-2025-36173

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

No fix yet
Fix from $1,600 2026-03-10
Budibase CRITICAL 9.0
CVE-2026-25737

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili…

Fix: after 3.24.0
Fix from $2,300 2026-03-09
Twake HIGH 8.8
CVE-2025-70038

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allow…

Mitigation only
Fix from $1,950 2026-03-09