Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 8.4
CVE-2026-5385

An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before …

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-30586

Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-33553

Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

Mitigation only
Fix from $1,600 2026-06-02
React Router MEDIUM 5.4
CVE-2026-33244

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization o…

Fix: 7.13.2+
Fix from $1,600 2026-06-02
Appsmith MEDIUM 5.4
CVE-2026-7299

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an auth…

Fix: 1.99+
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.9
CVE-2026-28116

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.1
CVE-2026-42685

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.4
CVE-2026-5191

The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.1
CVE-2026-34907

Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.1
CVE-2025-52759

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XS…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.4
CVE-2026-4080

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.4
CVE-2026-4081

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. Thi…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.4
CVE-2026-8885

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.5
CVE-2025-5085

The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-1450

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-1451

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.4
CVE-2026-2382

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX ac…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-2425

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to,…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.4
CVE-2026-3722

The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cros…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 6.1
CVE-2026-10510

Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versio…

Mitigation only
Fix from $1,600 2026-06-02
Kiteworks HIGH 8.2
CVE-2026-24752

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…

Fix: 9.3.0+
Fix from $1,950 2026-06-01
Kiteworks MEDIUM 5.4
CVE-2026-24754

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authentic…

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks HIGH 8.2
CVE-2026-24751

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…

Fix: 9.3.0+
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-42676

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects m…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.1
CVE-2026-42678

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based …

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.1
CVE-2026-48839

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. …

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.1
CVE-2026-48865

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. Thi…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 5.4
CVE-2026-48559

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScri…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.1
CVE-2026-42683

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS …

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.1
CVE-2026-42681

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This iss…

Mitigation only
Fix from $1,950 2026-06-01