Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Grav MEDIUM 5.4
CVE-2020-37256

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users wit…

Fix: 1.6.30+
Fix from $1,600 2026-06-25
Build Of Keycloak HIGH 7.3
CVE-2026-9086

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Librechat MEDIUM 5.4
CVE-2026-54025

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown arti…

Fix: after 0.7.8
Fix from $1,600 2026-06-25
K2 MEDIUM 6.1
CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

Fix: after 2.26
Fix from $1,600 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56051

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56071

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56006

Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56014

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56042

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.1
CVE-2026-56005

Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
GitLab MEDIUM 5.4
CVE-2026-10086

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ce…

Fix: 18.11.6 / 19.0.3+
Fix from $1,600 2026-06-25
GitLab MEDIUM 6.1
CVE-2026-10712

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that unde…

Fix: 18.11.6 / 19.0.3+
Fix from $1,600 2026-06-25
Unclassified MEDIUM 6.4
CVE-2026-10833

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t…

Mitigation only
Fix from $1,600 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9780

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authe…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-7569

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authe…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Cacti MEDIUM 6.1
CVE-2026-39900

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in th…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54067

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <st…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.1
CVE-2026-54070

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar packag…

No fix yet
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54158

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolate…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 8.7
CVE-2026-54759

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in t…

Mitigation only
Fix from $2,300 2026-06-24
Cacti MEDIUM 6.1
CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Unclassified HIGH 8.9
CVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb,…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-11998

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScr…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-53950

@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.7
CVE-2026-49220

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged use…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.1
CVE-2026-50701

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled …

Mitigation only
Fix from $1,600 2026-06-24
Access Manager MEDIUM 6.1
CVE-2026-11878

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scrip…

Fix: 5.1+
Fix from $1,600 2026-06-24
N8n MEDIUM 5.4
CVE-2026-56358

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the …

Fix: 1.123.25 / 2.11.2+
Fix from $1,600 2026-06-24