Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.1
CVE-2026-16583

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded S…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-8790

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in a…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-16143

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field o…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-51144

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-52370

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in th…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.7
CVE-2026-70492

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Mark…

Patch available
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.0
CVE-2026-70588

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize impor…

Patch available
Fix from $1,600 2026-08-04
Unclassified HIGH 8.5
CVE-2026-65986

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha…

Patch available
Fix from $1,950 2026-08-04
Unclassified HIGH 8.2
CVE-2026-70486

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl ifr…

Patch available
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.0
CVE-2026-66300

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitr…

Patch available
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-10032

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-67196

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaS…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc.…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX action…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-52520

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authen…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-49131

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privile…

Patch available
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-49132

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScrip…

Patch available
Fix from $1,600 2026-08-03
Oaskit MEDIUM 6.1
CVE-2026-66296

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default H…

Fix available
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-38444

osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitizati…

Patch available
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-38446

A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-contro…

Patch available
Fix from $1,600 2026-08-03
Angular MEDIUM 6.1
CVE-2026-69149

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,…

Fix: 20.3.27 / 21.2.19+
Fix from $1,600 2026-08-03
Angular MEDIUM 6.1
CVE-2026-69151

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,…

Fix: 20.3.27 / 21.2.19+
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-18243

Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view prin…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-69092

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messag…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-69075

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted …

Patch available
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-15383

The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauth…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-15931

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval reque…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-13340

The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it regist…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us…

No fix yet
Fix from $1,600 2026-08-02