Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.1
CVE-2026-57427

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.1
CVE-2026-57428

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-27403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.9
CVE-2026-24628

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.9
CVE-2025-68081

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.1
CVE-2026-65756

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15794

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versio…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15394

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15404

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15646

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-14481

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Script…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-9635

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-9729

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.2
CVE-2026-12421

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.1
CVE-2026-9066

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.2
CVE-2026-7232

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and inclu…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-7534

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-64795

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.1
CVE-2026-64828

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML…

No fix yet
Fix from $1,600 2026-07-22
Unclassified CRITICAL 9.3
CVE-2026-8152

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is dep…

No fix yet
Fix from $2,300 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65592

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the …

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65597

n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders …

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-63264

Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vu…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.4
CVE-2026-15787

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 8.8
CVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint a…

No fix yet
Fix from $1,950 2026-07-22
Webcenter Content HIGH 8.8
CVE-2026-60664

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.0
CVE-2026-60646

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.0
CVE-2026-60650

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60634

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60635

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21