Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Sharepoint Server MEDIUM 5.4
CVE-2026-45465

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45453

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Svelte MEDIUM 6.1
CVE-2026-42573

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on e…

Fix: 5.55.7+
Fix from $1,600 2026-06-09
Svelte MEDIUM 6.1
CVE-2026-42599

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event han…

Fix: 5.55.7+
Fix from $1,600 2026-06-09
Azure Stack Edge HIGH 8.4
CVE-2026-41098

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spo…

Fix: 3.3.2604.3097+
Fix from $1,950 2026-06-09
Experience Manager MEDIUM 5.4
CVE-2026-34692

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…

Fix: 6.5.25.0 / 2026.5.0+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 6.1
CVE-2026-33113

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.1
CVE-2026-47348

Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without san…

Patch available
Fix from $1,600 2026-06-09
Unclassified HIGH 8.7
CVE-2026-41031

A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8599

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8677

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Wid…

Mitigation only
Fix from $1,600 2026-06-09
Answer MEDIUM 5.4
CVE-2026-34033

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Qts MEDIUM 6.1
CVE-2026-41539

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit …

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8977

The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in version…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8895

The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and …

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-7662

The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8841

The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribut…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8880

The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the r…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8882

The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-8883

The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up t…

Mitigation only
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41845

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting …

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41846

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTM…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-11603

The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-10024

The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to,…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-10738

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all version…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-5714

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, an…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified HIGH 7.2
CVE-2026-7556

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and incl…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.4
CVE-2026-10862

The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2…

No fix yet
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2026-44746

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL …

Mitigation only
Fix from $1,600 2026-06-09
Unclassified HIGH 7.0
CVE-2026-44541

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.j…

Patch available
Fix from $1,950 2026-06-08