Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.1
CVE-2026-6953

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML …

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.1
CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerabil…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.1
CVE-2026-54889

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL sch…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.1
CVE-2026-57958

Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript i…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57336

Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57337

Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57338

Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57328

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57329

Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-57330

Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57333

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57320

Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.1
CVE-2026-57326

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Mitigation only
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.4
CVE-2026-11783

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored C…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-13295

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-11597

The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versio…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.1
CVE-2026-13245

The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, …

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-13335

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions u…

Mitigation only
Fix from $1,600 2026-06-27
Koha MEDIUM 6.1
CVE-2026-50765

A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.1…

Fix: after 25.11.00
Fix from $1,600 2026-06-26
Koha MEDIUM 5.4
CVE-2026-50766

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an au…

Fix: after 25.11.00
Fix from $1,600 2026-06-26
Koha MEDIUM 5.4
CVE-2026-50767

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions all…

Fix: after 25.11.00
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.4
CVE-2026-52781

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricte…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.7
CVE-2026-44696

OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Saniti…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57651

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.9
CVE-2026-57656

Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

No fix yet
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57650

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

No fix yet
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57638

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

No fix yet
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57629

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.1
CVE-2026-57325

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57431

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

Mitigation only
Fix from $1,600 2026-06-26