Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-4804

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is …

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-9756

The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8351

The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in version…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 7.2
CVE-2026-9148

The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-9626

The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in v…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8489

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8892

The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Addre…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 7.2
CVE-2026-13040

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-12731

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-12734

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.4
CVE-2026-59102

Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in oth…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.4
CVE-2026-58579

RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via norma…

Patch available
Fix from $1,600 2026-07-02
Netdata MEDIUM 6.1
CVE-2025-71385

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generat…

Fix: 2.3.1+
Fix from $1,600 2026-07-02
Unclassified HIGH 7.0
CVE-2026-8699

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insuffi…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.4
CVE-2026-4772

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored …

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.9
CVE-2026-57762

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57763

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57764

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57754

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57755

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57684

Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.

No fix yet
Fix from $1,600 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57686

Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57674

Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57675

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57678

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected X…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57682

Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.6
CVE-2026-57625

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57670

Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.

No fix yet
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57671

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57672

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.

Mitigation only
Fix from $1,950 2026-07-02