Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-12231

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.1
CVE-2026-14841

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-14864

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.8
CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.6
CVE-2026-67352

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.2
CVE-2026-67333

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-67328

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign …

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.1
CVE-2025-71404

better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where t…

Patch available
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-18062

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block I…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.1
CVE-2026-18344

The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-18435

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Blo…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-16684

The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-16685

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and incl…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.1
CVE-2026-17571

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-16090

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Si…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-16091

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Si…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-15644

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in a…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-15645

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-15649

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all vers…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-15662

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-15950

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-13458

The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all versions up …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.2
CVE-2026-15052

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form F…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-15234

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-15262

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-14292

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package template…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.1
CVE-2026-13725

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJ…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-12696

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the…

No fix yet
Fix from $1,600 2026-08-01