Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Digital Experience Compose MEDIUM 6.1
CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute a…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified MEDIUM 5.4
CVE-2026-50591

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

Mitigation only
Fix from $1,600 2026-06-05
Unclassified MEDIUM 6.4
CVE-2026-50592

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

Mitigation only
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.1
CVE-2026-11273

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engag…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.1
CVE-2026-11186

Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.8
CVE-2026-11166

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.1
CVE-2026-11150

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Unclassified HIGH 7.6
CVE-2026-41518

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In versions 4.9.0 thro…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.3
CVE-2025-65640

Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanit…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified HIGH 7.1
CVE-2025-67448

The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 8.9
CVE-2026-43984

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated u…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 5.4
CVE-2019-25742

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.4
CVE-2019-25743

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scrip…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.4
CVE-2019-25744

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.1
CVE-2019-25737

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts thro…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.4
CVE-2019-25739

GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.1
CVE-2019-25731

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submit…

No fix yet
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.1
CVE-2026-42840

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering …

Mitigation only
Fix from $1,600 2026-06-03
Koha MEDIUM 5.4
CVE-2026-26378

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice fe…

Fix: after 25.11.00
Fix from $1,600 2026-06-03
Unclassified MEDIUM 6.3
CVE-2026-39107

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or enco…

Mitigation only
Fix from $1,600 2026-06-03
Webex Meetings MEDIUM 6.1
CVE-2026-20233

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-sit…

Mitigation only
Fix from $1,600 2026-06-03
Unclassified HIGH 8.4
CVE-2026-42321

GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS paylo…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified CRITICAL 9.0
CVE-2026-36748

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Mitigation only
Fix from $2,300 2026-06-03
Unclassified MEDIUM 5.1
CVE-2022-31114

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom adm…

Mitigation only
Fix from $1,600 2026-06-03
Unclassified MEDIUM 5.1
CVE-2026-47324

ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objec…

Mitigation only
Fix from $1,600 2026-06-03
T Mac Plus MEDIUM 5.4
CVE-2025-14773

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus:…

Mitigation only
Fix from $1,600 2026-06-03
Unclassified HIGH 7.1
CVE-2025-15654

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This i…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.1
CVE-2026-40108

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. Th…

Mitigation only
Fix from $1,950 2026-06-02
Opencti MEDIUM 6.1
CVE-2026-35212

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to X…

Fix: 7.260227.0+
Fix from $1,600 2026-06-02
Authentik CRITICAL 9.3
CVE-2026-42849

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow …

Fix: 2025.12.5 / 2026.2.3+
Fix from $2,300 2026-06-02