Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.1
CVE-2026-57379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Sto…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57380

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-le…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57381

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57382

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-li…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57383

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57387

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue aff…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57368

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Refle…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57369

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allow…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Eleme…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.1
CVE-2026-57363

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-57365

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for As…

Mitigation only
Fix from $1,600 2026-07-13
Helix Ultimate MEDIUM 6.1
CVE-2026-57829

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an un…

Fix: after 2.2.6
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.1
CVE-2026-15552

Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject per…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 8.8
CVE-2026-61875

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortM…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified HIGH 8.8
CVE-2026-61876

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML ma…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified MEDIUM 6.4
CVE-2026-1382

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15010

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Addit…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-6939

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all …

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-12126

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-13378

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all ve…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15096

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15097

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2025-13968

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboar…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-5743

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-13114

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Us…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified CRITICAL 9.8
CVE-2026-11913

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Drupal Canvas MEDIUM 6.1
CVE-2026-58588

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scriptin…

Fix: 1.4.2 / 1.5.2+
Fix from $1,600 2026-07-10
Colorbox MEDIUM 5.4
CVE-2026-58591

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XS…

Fix: 2.1.5+
Fix from $1,600 2026-07-10
Drupal Canvas MEDIUM 6.1
CVE-2026-58587

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scriptin…

Fix: 1.4.2 / 1.5.2+
Fix from $1,600 2026-07-10
Drupal MEDIUM 5.4
CVE-2026-55808

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10