Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-6742

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.4
CVE-2025-14785

The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Store…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-11798

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.4
CVE-2026-10570

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versi…

Mitigation only
Fix from $1,600 2026-07-08
Coder MEDIUM 5.4
CVE-2026-55437

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `Ag…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.4
CVE-2026-36162

An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbi…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.4
CVE-2026-36163

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.1
CVE-2026-55647

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue…

Patch available
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48954

Improper validation leads to a generic XSS vector in the language override feature.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48949

Lack of validation leads to an XSS vulnerability in the MFA management views.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48950

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48951

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48952

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48953

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.5
CVE-2025-12799

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped ch…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.4
CVE-2026-8309

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.1
CVE-2026-8306

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.4
CVE-2026-11328

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up …

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.1
CVE-2026-59710

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properl…

Patch available
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.1
CVE-2026-59711

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When…

Mitigation only
Fix from $1,600 2026-07-06
Hugo MEDIUM 5.4
CVE-2026-58402

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string …

Fix: 0.163.3+
Fix from $1,600 2026-07-06
Hugo MEDIUM 6.1
CVE-2026-50133

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (ty…

Fix: 0.162.0+
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.4
CVE-2026-12154

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attr…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified HIGH 8.2
CVE-2025-53831

DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO fo…

Mitigation only
Fix from $1,950 2026-07-06
Api Control Plane MEDIUM 6.1
CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c…

Fix: 2.0.0.404 / 2.0.0.424+
Fix from $1,600 2026-07-06
Edge Chromium MEDIUM 6.1
CVE-2026-58524

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.1
CVE-2026-58298

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium HIGH 7.1
CVE-2026-57977

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Unclassified HIGH 8.7
CVE-2026-28737

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file…

Patch available
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.1
CVE-2026-4322

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertisi…

Mitigation only
Fix from $1,600 2026-07-03