Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
React Router MEDIUM 6.1
CVE-2026-53667

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects fro…

Fix: 7.18.0+
Fix from $1,600 2026-07-27
React Router MEDIUM 6.9
CVE-2026-53668

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…

Fix: 7.13.0+
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.2
CVE-2026-66824

A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree dire…

Patch available
Fix from $2,300 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-66825

Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as u…

Patch available
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.1
CVE-2026-59729

Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in rende…

Patch available
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66031

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66029

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66030

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to injec…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 8.6
CVE-2026-59239

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user …

Patch available
Fix from $1,950 2026-07-27
Wicket MEDIUM 6.1
CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.10.0+
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.6
CVE-2026-66395

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to exe…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.4
CVE-2026-66396

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cr…

Mitigation only
Fix from $1,950 2026-07-27
Unclassified HIGH 8.7
CVE-2026-66394

SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to ex…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66434

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66445

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66448

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.9
CVE-2026-66475

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66433

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.9
CVE-2026-65557

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-65561

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-65562

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.9
CVE-2026-65563

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-59559

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 7.1
CVE-2026-59553

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.1
CVE-2026-59556

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.1
CVE-2026-59558

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.3
CVE-2026-14856

A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficien…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.1
CVE-2026-65764

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XS…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.8
CVE-2026-14827

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a p…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.1
CVE-2026-13400

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root caus…

No fix yet
Fix from $1,600 2026-07-27