Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.2
CVE-2026-7517

The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' param…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-2387

The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to th…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.1
CVE-2026-13015

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13246

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13443

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.2
CVE-2026-13731

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conv…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-12135

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute i…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-11380

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to…

Mitigation only
Fix from $1,600 2026-07-01
Thunderbird MEDIUM 6.5
CVE-2026-57963

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the ch…

Fix: 140.12.1 / 152.0.1+
Fix from $1,600 2026-07-01
N8n MEDIUM 5.4
CVE-2026-56356

n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html l…

Fix: 1.123.27 / 2.13.3+
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.1
CVE-2026-50040

Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An …

Mitigation only
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-14147

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-14145

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-14068

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in sp…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-14000

Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-14001

Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 5.4
CVE-2026-13977

Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXS…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.1
CVE-2026-13836

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Enterprise Server MEDIUM 5.4
CVE-2026-10585

A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary Ja…

Fix: 3.16.20 / 3.17.17+
Fix from $1,600 2026-06-30
Websphere Application Server MEDIUM 6.1
CVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 6.4
CVE-2025-36320

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.4
CVE-2025-36323

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em…

Mitigation only
Fix from $1,600 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Unclassified HIGH 7.2
CVE-2026-10513

The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' an…

Mitigation only
Fix from $1,950 2026-06-30
Coldfusion HIGH 8.8
CVE-2026-48307

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this …

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.1
CVE-2026-8403

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer In…

Mitigation only
Fix from $1,600 2026-06-30
Activemq MEDIUM 6.1
CVE-2026-52760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. …

Fix: 5.19.8 / 6.2.7+
Fix from $1,600 2026-06-30
Unclassified HIGH 7.2
CVE-2026-8141

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all v…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.1
CVE-2026-6954

Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or i…

Mitigation only
Fix from $1,600 2026-06-30