Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-12157

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 6.4
CVE-2026-1856

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up…

Mitigation only
Fix from $1,600 2026-06-19
Pgadmin 4 MEDIUM 5.4
CVE-2026-12047

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /go…

Fix: 9.16+
Fix from $1,600 2026-06-19
Pgadmin 4 MEDIUM 5.4
CVE-2026-12048

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse message…

Fix: 9.16+
Fix from $1,600 2026-06-19
Coturn MEDIUM 5.4
CVE-2026-43915

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerabili…

Fix: 4.11.0+
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.1
CVE-2026-11982

Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.

Patch available
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.9
CVE-2026-56007

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.9
CVE-2026-56009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.1
CVE-2026-54219

UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low p…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.1
CVE-2026-54221

UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrar…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.4
CVE-2026-8039

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' sh…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.4
CVE-2026-2021

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 7.6
CVE-2026-55746

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 6.4
CVE-2026-12098

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all v…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.4
CVE-2026-12136

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode …

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.1
CVE-2026-12137

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cros…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.4
CVE-2026-11402

The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link'…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified CRITICAL 9.3
CVE-2026-48768

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified MEDIUM 6.1
CVE-2026-44644

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a …

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.1
CVE-2026-54386

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arb…

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.8
CVE-2026-48821

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Sy…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.8
CVE-2026-48822

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTM…

Mitigation only
Fix from $1,600 2026-06-17
Plane MEDIUM 5.4
CVE-2026-10850

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr…

No fix yet
Fix from $1,600 2026-06-17
Unclassified HIGH 7.1
CVE-2026-40720

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 7.1
CVE-2025-69140

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 7.1
CVE-2025-68524

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.4
CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 7.1
CVE-2026-9570

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.4
CVE-2026-8494

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 7.1
CVE-2026-8089

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properl…

Mitigation only
Fix from $1,950 2026-06-17