Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Chrome MEDIUM 5.4
CVE-2026-9971

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in speci…

Fix: 148.0.7778.216+
Fix from $1,600 2026-05-28
Unclassified HIGH 8.5
CVE-2026-45343

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-44657

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF…

Patch available
Fix from $1,950 2026-05-28
Unclassified HIGH 8.6
CVE-2026-44655

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which…

Patch available
Fix from $1,950 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-41897

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target parameter on return_dynamic_…

Patch available
Fix from $1,600 2026-05-28
Kibana MEDIUM 5.4
CVE-2026-42401

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elas…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.0
CVE-2026-43979

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HT…

Patch available
Fix from $1,600 2026-05-28
Meshcore Card CRITICAL 9.6
CVE-2026-45323

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-…

Fix: 0.3.3+
Fix from $2,300 2026-05-28
Unclassified HIGH 8.7
CVE-2026-45348

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes…

Mitigation only
Fix from $1,950 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47759

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attribu…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47760

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope …

Fix: 7.1.0+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47761

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47762

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments.…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.4
CVE-2026-4334

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all …

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.1
CVE-2024-47097

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code v…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.1
CVE-2024-47096

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code v…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.3
CVE-2026-9806

A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to the patched release. Notific…

Patch available
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.1
CVE-2026-7660

The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and includ…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.4
CVE-2026-6427

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 7.2
CVE-2026-7052

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' …

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.2
CVE-2026-7634

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and inclu…

Patch available
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.4
CVE-2026-9644

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortc…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 7.2
CVE-2026-2374

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all ve…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.7
CVE-2026-42197

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulner…

Patch available
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.4
CVE-2026-42877

FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 8.1
CVE-2026-48149

Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) strai…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.6
CVE-2026-46426

Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.4
CVE-2026-38931

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.1
CVE-2026-49102

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml i…

Patch available
Fix from $1,600 2026-05-27
Buildgraph View MEDIUM 5.5
CVE-2026-48927

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploita…

Fix: after 1.8
Fix from $1,600 2026-05-27