Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-45797

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG fil…

Patch available
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.0
CVE-2026-35198

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a l…

Patch available
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.9
CVE-2026-59238

Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maa…

Patch available
Fix from $1,600 2026-07-20
Unclassified HIGH 8.7
CVE-2026-45270

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` …

No fix yet
Fix from $1,950 2026-07-20
Api Control Plane MEDIUM 6.1
CVE-2026-2445

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi…

Fix: 4.2.0.195 / 4.3.0.106+
Fix from $1,600 2026-07-20
Unclassified HIGH 7.1
CVE-2026-9833

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters b…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-12970

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cr…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-12592

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analyti…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.8
CVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API befor…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-45138

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to saniti…

No fix yet
Fix from $1,600 2026-07-20
Lollms MEDIUM 5.4
CVE-2026-12228

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint …

Fix: after 2.1.0
Fix from $1,600 2026-07-18
View Component HIGH 8.7
CVE-2026-54498

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewCompon…

Fix: 4.12.0+
Fix from $1,950 2026-07-17
Engineering Ai Hub CRITICAL 9.3
CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…

Fix: 1.3.0+
Fix from $2,300 2026-07-17
Unclassified HIGH 7.0
CVE-2026-9588

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template fun…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 8.6
CVE-2026-9585

An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application f…

Mitigation only
Fix from $1,950 2026-07-17
Ux MEDIUM 5.4
CVE-2026-49216

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX …

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Ux MEDIUM 6.1
CVE-2026-49210

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::cre…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Unclassified HIGH 8.7
CVE-2026-58148

Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-51081

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows att…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-10525

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the ad…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-15094

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, an…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-15161

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-15759

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-11324

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'red…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.2
CVE-2026-15395

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-2594

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to ins…

No fix yet
Fix from $1,600 2026-07-17
Windows Admin Center MEDIUM 6.1
CVE-2026-58643

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo…

Fix: 2511+
Fix from $1,600 2026-07-16
Sharepoint Server MEDIUM 5.4
CVE-2026-62826

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-16
Unclassified HIGH 8.4
CVE-2026-45368

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image block…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified HIGH 8.5
CVE-2026-44175

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list fie…

No fix yet
Fix from $1,950 2026-07-16