Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.5
CVE-2026-39540

Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39514

Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39507

Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-39491

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39449

Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-39451

Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39463

Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-34900

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-34902

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39435

Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-39447

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2026-23970

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2025-68840

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2025-68851

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2025-68872

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.6
CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a craft…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified MEDIUM 5.4
CVE-2026-50876

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.1
CVE-2026-37216

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.1
CVE-2026-36521

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.1
CVE-2026-49294

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to refl…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2025-15659

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 5.9
CVE-2025-15658

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified HIGH 7.2
CVE-2016-20084

WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify c…

No fix yet
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.4
CVE-2016-20070

WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated…

No fix yet
Fix from $1,600 2026-06-15
Unclassified HIGH 7.2
CVE-2016-20066

WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitiz…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-5513

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-custo…

No fix yet
Fix from $1,950 2026-06-13
Unclassified MEDIUM 6.4
CVE-2026-3297

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in…

Mitigation only
Fix from $1,600 2026-06-13
Unclassified MEDIUM 6.4
CVE-2026-9629

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due …

Mitigation only
Fix from $1,600 2026-06-13
Unclassified MEDIUM 6.4
CVE-2026-9134

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to…

Mitigation only
Fix from $1,600 2026-06-13
Unclassified HIGH 7.2
CVE-2026-9109

The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site…

Mitigation only
Fix from $1,950 2026-06-13