Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Webcenter Content HIGH 8.8
CVE-2026-60636

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

Mitigation only
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60637

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60638

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60639

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60633

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.1
CVE-2026-52475

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file

No fix yet
Fix from $1,600 2026-07-21
Fogproject HIGH 8.7
CVE-2026-47685

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenti…

Fix: 1.5.10.1832+
Fix from $1,950 2026-07-21
Fogproject HIGH 8.7
CVE-2026-47687

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectFor…

Fix: 1.5.10.1832+
Fix from $1,950 2026-07-21
Fogproject MEDIUM 5.2
CVE-2026-47689

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow(…

Fix: 1.5.10.1832+
Fix from $1,600 2026-07-21
Unclassified HIGH 8.1
CVE-2026-50758

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Mitigation only
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-55081

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflect…

Patch available
Fix from $1,950 2026-07-21
Serv U MEDIUM 6.2
CVE-2026-28315

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclos…

Fix: 2026.3+
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.3
CVE-2026-65048

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatab…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 5.4
CVE-2026-64628

Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads con…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.4
CVE-2026-15145

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fanc…

Patch available
Fix from $1,600 2026-07-21
Unclassified HIGH 8.8
CVE-2026-11767

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.4
CVE-2026-15156

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read…

No fix yet
Fix from $1,600 2026-07-21
Devops Plan MEDIUM 6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain brows…

Fix: 3.0.5+
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.1
CVE-2026-51025

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageCo…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.4
CVE-2026-12900

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/i…

No fix yet
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 5.4
CVE-2026-44229

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a…

Fix: 5.0.10 / 6.0.3+
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 6.1
CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not in…

Fix: 5.0.10 / 6.0.3+
Fix from $1,600 2026-07-20
Unclassified HIGH 8.6
CVE-2026-60028

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.1
CVE-2026-60029

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60034

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS …

No fix yet
Fix from $2,300 2026-07-20
Request Tracker MEDIUM 6.1
CVE-2026-44227

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scri…

Fix: 6.0.3+
Fix from $1,600 2026-07-20
Request Tracker MEDIUM 5.4
CVE-2026-44228

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Script…

Fix: 6.0.3+
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.3
CVE-2026-39878

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.1
CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The applicat…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-6793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT …

No fix yet
Fix from $1,600 2026-07-20