Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified CRITICAL 9.0
CVE-2026-73044

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73050

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73041

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject ma…

No fix yet
Fix from $5,750 2026-08-15
Unclassified MEDIUM 5.4
CVE-2026-14230

The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a …

Fix unknown
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.4
CVE-2026-17090

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module '…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.2
CVE-2026-16145

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ac…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.4
CVE-2026-15948

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.2
CVE-2026-13360

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' param…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 7.2
CVE-2026-14433

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_i…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.3
CVE-2026-17209

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.5
CVE-2026-63361

LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-53472

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to sto…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.4
CVE-2026-72832

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Co…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.4
CVE-2026-72821

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.2
CVE-2026-19794

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input s…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribut…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.2
CVE-2026-18109

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.6
CVE-2026-73417

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-56858

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially lead…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73531

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScrip…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-49864

wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73038

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.1
CVE-2026-73648

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restrict…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73572

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insuff…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.1
CVE-2026-19744

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the ap…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-28154

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerc…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73357

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73340

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

No fix yet
Fix from $4,000 2026-08-13