Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-13252

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.4
CVE-2026-13704

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.4
CVE-2026-10089

The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to,…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.9
CVE-2026-55791

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerab…

Patch available
Fix from $1,600 2026-07-02
Unclassified HIGH 7.4
CVE-2026-55790

Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub ac…

Patch available
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-55793

Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaSc…

Patch available
Fix from $1,600 2026-07-01
Wagtail HIGH 7.3
CVE-2026-54263

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2026-07-01
Unclassified HIGH 7.2
CVE-2026-58263

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.4
CVE-2026-54720

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.6
CVE-2026-55660

Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich…

Patch available
Fix from $1,950 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-14358

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Ext…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-57722

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored X…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-57737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Ph…

Mitigation only
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-58037

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-58038

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vu…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 5.4
CVE-2026-58028

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedi…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-58030

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeS…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.1
CVE-2026-58032

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-5220

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.4
CVE-2026-6283

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…

Mitigation only
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 5.4
CVE-2026-58031

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice MEDIUM 5.4
CVE-2026-53907

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl…

Mitigation only
Fix from $1,600 2026-07-01
Open Vsx HIGH 8.7
CVE-2026-13323

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Sec…

Fix: 1.0.2+
Fix from $1,950 2026-07-01
Unclassified HIGH 7.2
CVE-2026-12142

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter i…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-10095

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.1
CVE-2026-12754

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-12732

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13733

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, a…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-9107

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field…

Mitigation only
Fix from $1,600 2026-07-01
Cargo MEDIUM 5.4
CVE-2026-58519

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…

Fix: 3.9.1+
Fix from $1,600 2026-07-01