Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.9
CVE-2026-75529

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint v…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-67925

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-63670

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through pack…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-50771

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.1
CVE-2026-33437

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.2
CVE-2026-75048

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-55674

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.3
CVE-2026-13202

A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2.

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.2
CVE-2026-74998

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.0
CVE-2026-74800

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.2
CVE-2026-10734

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and includi…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.2
CVE-2026-13424

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_u…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-2357

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.1
CVE-2026-19712

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instru…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-16758

The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and includin…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-16775

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Sho…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-18402

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Bl…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.4
CVE-2026-13712

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attribu…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15604

The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_co…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15790

The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and inclu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-15002

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.0
CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73053

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73042

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open …

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73043

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go temp…

No fix yet
Fix from $5,750 2026-08-15