Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.1
CVE-2026-65762

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XS…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.7
CVE-2026-47743

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da…

Patch available
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.1
CVE-2026-65697

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attac…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48536

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated a…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48537

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48538

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48539

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authent…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48530

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated at…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48531

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attack…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48532

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authent…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48534

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers t…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48535

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated …

No fix yet
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wra…

Fix: 3.3.2+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HA…

Fix: 3.4.0+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.at…

Fix: 3.3.2+
Fix from $1,600 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form node…

Fix: 3.4.7+
Fix from $1,600 2026-07-23
Dompurify HIGH 7.2
CVE-2026-65898

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to p…

Fix: 3.4.11+
Fix from $1,950 2026-07-23
Dompurify MEDIUM 6.1
CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT…

Fix: 3.4.8+
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.9
CVE-2026-65550

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65605

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren…

Patch available
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65606

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references …

Patch available
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65533

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.9
CVE-2026-65534

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.9
CVE-2026-65538

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65522

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65527

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65528

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.1
CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.1
CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65514

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

No fix yet
Fix from $1,600 2026-07-23