Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.2
CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-9620

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.1
CVE-2026-8628

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-8865

The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-8896

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.1
CVE-2026-8622

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, an…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.2
CVE-2026-10091

The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.2
CVE-2026-10092

The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all v…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.2
CVE-2026-3652

The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX a…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-11614

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.2
CVE-2026-56785

FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without pr…

Patch available
Fix from $1,950 2026-06-23
Unclassified MEDIUM 5.1
CVE-2026-53929

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authenticated uploader could deliv…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified HIGH 7.4
CVE-2026-47383

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HTML in row comments that execu…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 8.4
CVE-2026-47387

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (packages/nc-gui/composables/useSh…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified MEDIUM 5.1
CVE-2026-47376

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScr…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.1
CVE-2026-46547

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning page.…

Mitigation only
Fix from $1,600 2026-06-23
Open Webui MEDIUM 5.4
CVE-2026-54011

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks f…

Fix: 0.9.6+
Fix from $1,600 2026-06-23
Open Webui HIGH 7.6
CVE-2026-54013

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user…

Fix: 0.9.6+
Fix from $1,950 2026-06-23
Unclassified CRITICAL 9.6
CVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X…

Patch available
Fix from $2,300 2026-06-23
N8n MEDIUM 5.4
CVE-2026-54301

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could conf…

Fix: 1.123.55 / 2.25.7+
Fix from $1,600 2026-06-23
N8n MEDIUM 5.4
CVE-2026-54302

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inje…

Fix: 1.123.55 / 2.25.7+
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.1
CVE-2026-34915

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit…

Mitigation only
Fix from $1,600 2026-06-23
N8n MEDIUM 5.4
CVE-2026-54303

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query param…

Fix: 2.24.0+
Fix from $1,600 2026-06-23
Unclassified MEDIUM 5.1
CVE-2026-11772

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arb…

Mitigation only
Fix from $1,600 2026-06-23
Crawl4ai MEDIUM 6.1
CVE-2026-56263

Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via in…

Fix: 0.8.7+
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.4
CVE-2026-4610

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message'…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.1
CVE-2026-10857

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry a…

Mitigation only
Fix from $1,600 2026-06-23
Open Vsx MEDIUM 5.4
CVE-2026-4983

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without …

Fix: 0.34.1+
Fix from $1,600 2026-06-23
Nuxt MEDIUM 6.1
CVE-2026-56698

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side scrip…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-22
Unclassified HIGH 7.6
CVE-2026-55409

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered …

Mitigation only
Fix from $1,950 2026-06-22