Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-3907

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-12924

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.2
CVE-2026-15298

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insu…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15299

The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' par…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15301

The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, a…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15292

The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode in…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15296

The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_prod…

No fix yet
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.1
CVE-2026-15297

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Sc…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15284

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, a…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15285

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.1
CVE-2026-11392

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.6
CVE-2026-59833

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engin…

Patch available
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.4
CVE-2026-58144

Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbit…

Mitigation only
Fix from $1,600 2026-07-09
Discourse MEDIUM 5.4
CVE-2026-55424

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently no…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,600 2026-07-09
Discourse MEDIUM 5.4
CVE-2026-53962

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and use…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,600 2026-07-09
Discourse CRITICAL 9.0
CVE-2026-53963

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-c…

Fix: 2026.1.5 / 2026.4.2+
Fix from $2,300 2026-07-09
Unclassified MEDIUM 5.4
CVE-2026-60120

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to…

Patch available
Fix from $1,600 2026-07-09
Unclassified HIGH 8.5
CVE-2026-54002

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::…

Patch available
Fix from $1,950 2026-07-09
Pan Os MEDIUM 6.1
CVE-2026-0279

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal featu…

Fix: 11.1.16 / 11.2.13+
Fix from $1,600 2026-07-09
Open Webui CRITICAL 9.0
CVE-2026-59214

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodid…

Fix: 0.10.0+
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-53987

The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::…

Patch available
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.4
CVE-2026-5005

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.2
CVE-2026-9253

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' …

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.2
CVE-2026-13441

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_back…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-5793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticare…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.3
CVE-2026-2342

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-6910

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `h…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-4653

The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up t…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-14343

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.2
CVE-2026-15000

The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all ve…

Mitigation only
Fix from $1,950 2026-07-09