Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-8613

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up …

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.4
CVE-2026-9019

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][att…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 8.8
CVE-2026-8071

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its ema…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.4
CVE-2025-8444

The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-S…

Mitigation only
Fix from $1,600 2026-06-10
Learning MEDIUM 5.4
CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user…

Fix: 2.52.0+
Fix from $1,600 2026-06-10
Openemr HIGH 8.7
CVE-2026-46518

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-sit…

Fix: 8.0.0.1+
Fix from $1,950 2026-06-10
Spring Security MEDIUM 5.4
CVE-2026-41003

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters…

Fix: 5.7.24 / 5.8.26+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 6.1
CVE-2026-25860

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arb…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-34417

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's…

Mitigation only
Fix from $1,600 2026-06-09
Coldfusion MEDIUM 5.4
CVE-2026-47933

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-34416

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.4
CVE-2026-25557

Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter valu…

Mitigation only
Fix from $1,600 2026-06-09
Focus HIGH 7.5
CVE-2026-11799

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

Fix: 151.3.1+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.4
CVE-2026-47106

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search funct…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-32856

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthentic…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.4
CVE-2026-36728

A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitr…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-36725

A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute ar…

Mitigation only
Fix from $1,600 2026-06-09
Experience Manager HIGH 8.0
CVE-2026-34693

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An at…

Fix: after 6.5.24.0
Fix from $1,950 2026-06-09
Experience Manager CRITICAL 9.3
CVE-2026-34691

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that coul…

Fix: after 6.5.24.0
Fix from $2,300 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48297

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48299

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48300

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48301

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48304

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-48560

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48266

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48268

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48271

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-48280

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-47993

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09