Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.2
CVE-2026-18325

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-16636

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stor…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-70440

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resultin…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70441

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cro…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.3
CVE-2026-9195

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-53992

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitra…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-17506

The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-71285

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted Jav…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.5
CVE-2026-71274

OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HT…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-71275

OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(reques…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-71249

299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) int…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71236

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71233

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (r…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.4
CVE-2026-7441

The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive`…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.4
CVE-2026-6972

The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-17532

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-17505

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versi…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-16942

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to user…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-16573

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to up…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-16583

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded S…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-8790

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in a…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-16143

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field o…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-51144

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-52370

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in th…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.7
CVE-2026-70492

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Mark…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.0
CVE-2026-70588

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize impor…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.5
CVE-2026-65986

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.2
CVE-2026-70486

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl ifr…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.0
CVE-2026-66300

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitr…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-10032

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent …

No fix yet
Fix from $1,600 2026-08-04