Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 8.7
CVE-2026-53608

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.1
CVE-2026-54393

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-contro…

Patch available
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-54395

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScrip…

Patch available
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.4
CVE-2026-53606

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of s…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified CRITICAL 9.3
CVE-2026-44990

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the def…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified HIGH 7.3
CVE-2026-45011

ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-45014

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-53568

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List Vi…

Mitigation only
Fix from $1,600 2026-06-12
Nuxt MEDIUM 5.4
CVE-2026-53722

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-47739

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-44205

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an a…

Mitigation only
Fix from $1,600 2026-06-12
Nuxt MEDIUM 5.4
CVE-2026-46342

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitr…

Fix: 3.21.6 / 4.4.5+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.4
CVE-2026-9125

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] short…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified HIGH 7.1
CVE-2026-42653

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This iss…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 8.1
CVE-2026-46489

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation.…

Patch available
Fix from $1,950 2026-06-11
GitLab HIGH 8.7
CVE-2026-8589

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that unde…

Fix: 18.10.8 / 18.11.5+
Fix from $1,950 2026-06-11
GitLab HIGH 8.7
CVE-2026-10087

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under …

Fix: 18.10.8 / 18.11.5+
Fix from $1,950 2026-06-11
Unclassified HIGH 7.1
CVE-2023-33999

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.6
CVE-2026-42558

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerabi…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 5.4
CVE-2026-53740

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can sche…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.4
CVE-2026-53741

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.4
CVE-2026-53742

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers …

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.1
CVE-2026-53737

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the co…

Mitigation only
Fix from $1,600 2026-06-10
Drawio MEDIUM 6.1
CVE-2026-46642

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file can execute arbitrary JavaScrip…

Fix: 29.7.12+
Fix from $1,600 2026-06-10
Splunk MEDIUM 5.4
CVE-2026-20258

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.250…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.9
CVE-2026-53693

A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, c…

Patch available
Fix from $1,600 2026-06-10
Migration Planner Ui MEDIUM 5.4
CVE-2026-53473

A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing …

Fix: 0.13.5+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.1
CVE-2026-45560

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/c…

Mitigation only
Fix from $1,600 2026-06-10
Jenkins MEDIUM 5.4
CVE-2026-53441

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic…

Fix: 2.555.3 / 2.568+
Fix from $1,600 2026-06-10
Unclassified HIGH 7.1
CVE-2026-49069

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This is…

Mitigation only
Fix from $1,950 2026-06-10