Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 8.5
CVE-2026-46686

Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php …

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-63081

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated att…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.2
CVE-2026-7543

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 d…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15021

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including,…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15099

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and includ…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-13755

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-12869

The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.1
CVE-2026-12978

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its p…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-11371

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the featu…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-15306

The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.2
CVE-2026-13042

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 …

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15652

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Blo…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-14987

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.6
CVE-2026-54458

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin.…

Patch available
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-50182

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI…

Patch available
Fix from $1,600 2026-07-15
Unclassified HIGH 7.7
CVE-2026-49279

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in …

Patch available
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-26719

Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request contain…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.3
CVE-2026-49867

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit …

Patch available
Fix from $1,600 2026-07-15
Argo Cd HIGH 8.7
CVE-2026-45738

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write ac…

Fix: 3.2.12 / 3.3.10+
Fix from $1,950 2026-07-15
Openwrt CRITICAL 9.6
CVE-2026-62948

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh…

Fix: 25.12.5+
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.0
CVE-2026-62378

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/prev…

Patch available
Fix from $2,300 2026-07-15
Unclassified MEDIUM 5.5
CVE-2026-9007

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected …

Mitigation only
Fix from $1,600 2026-07-15
Stirling Pdf MEDIUM 6.1
CVE-2026-41580

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf en…

Fix: 2.0.0+
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-61453

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page cont…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.6
CVE-2026-57833

Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-58077

Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate…

Mitigation only
Fix from $1,950 2026-07-15
Twig MEDIUM 5.4
CVE-2026-47730

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() in…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig MEDIUM 5.4
CVE-2026-46637

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe =>…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Jadx MEDIUM 5.0
CVE-2026-42447

jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java…

Fix: 1.5.6+
Fix from $1,600 2026-07-14
Dompurify MEDIUM 6.1
CVE-2026-49978

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow c…

Fix: 3.4.7+
Fix from $1,600 2026-07-14