Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-8887

The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8891

The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8894

The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8897

The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8898

The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including,…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8867

The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versi…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8868

The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, an…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8869

The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and in…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8870

The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8871

The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8872

The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8873

The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8837

The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8842

The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8844

The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including,…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8845

The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and inc…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8846

The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. Th…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8847

The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insuffi…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8866

The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8048

The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shor…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8698

The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insuffic…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8701

The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-tick…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8702

The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortco…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8703

The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.1
CVE-2026-8707

The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-8040

The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.1
CVE-2026-6268

The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX han…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.4
CVE-2026-6287

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.7
CVE-2026-48999

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such m…

No fix yet
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.4
CVE-2026-9022

The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and incl…

No fix yet
Fix from $1,600 2026-05-27