Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-3639

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in a…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.2
CVE-2026-18146

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73422

Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animatio…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73415

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.7
CVE-2026-73329

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.4
CVE-2026-72787

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-49466

Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (X…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-19657

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visitin…

No fix yet
Fix from $4,000 2026-08-12
I MEDIUM 5.4
CVE-2026-18099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-cont…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.7
CVE-2026-15216

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.7
CVE-2026-15217

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.7
CVE-2026-16627

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/temp…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-48550

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An u…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string value…

No fix yet
Fix from $4,000 2026-08-12
I MEDIUM 5.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.0
CVE-2026-65937

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-73374

A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tag…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.9
CVE-2026-57858

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows a…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attacke…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-19217

The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, w…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-17013

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block,…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-16066

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowin…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-15249

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing use…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-9318

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitra…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.7
CVE-2026-73031

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browser…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.7
CVE-2026-48413

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.7
CVE-2026-48414

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…

No fix yet
Fix from $4,900 2026-08-11