Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.8
CVE-2026-14318

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-14592

The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option v…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-13330

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upl…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-14207

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, a…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-11881

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside…

No fix yet
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17962

Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) vi…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 5.4
CVE-2026-17903

Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to inject scri…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17878

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17845

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17853

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process t…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17827

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17818

Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) …

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17797

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 5.4
CVE-2026-17734

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS)…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 5.4
CVE-2026-17728

Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXS…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-65337

Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.

No fix yet
Fix from $1,600 2026-07-29
Gridbox MEDIUM 6.1
CVE-2026-66490

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Ro Csvi MEDIUM 6.1
CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

Fix: 9.11.0+
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-7436

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-8791

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.2
CVE-2026-16597

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billin…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.2
CVE-2026-16655

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.2
CVE-2026-13425

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and includi…

No fix yet
Fix from $1,950 2026-07-29
Link Library MEDIUM 6.1
CVE-2026-18197

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS).…

Fix: 7.9.4+
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.8
CVE-2026-13605

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into th…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.1
CVE-2026-14234

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-12939

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletter…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-15735

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17161

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17162

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' B…

No fix yet
Fix from $1,600 2026-07-29