Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.5
CVE-2026-40607

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect e…

Patch available
Fix from $1,950 2026-05-22
Unclassified HIGH 8.5
CVE-2026-39970

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified MEDIUM 5.4
CVE-2026-39964

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble con…

Patch available
Fix from $1,600 2026-05-22
Unclassified HIGH 8.7
CVE-2026-28445

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIc…

Patch available
Fix from $1,950 2026-05-22
Unclassified MEDIUM 6.1
CVE-2026-36226

Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decry…

Mitigation only
Fix from $1,600 2026-05-22
Net MEDIUM 6.1
CVE-2026-42506

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in app…

Fix: 0.55.0+
Fix from $1,600 2026-05-22
Unclassified MEDIUM 6.4
CVE-2026-9104

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified MEDIUM 6.1
CVE-2026-6864

The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, a…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified MEDIUM 6.4
CVE-2026-7509

The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` att…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified MEDIUM 6.1
CVE-2026-3481

The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and includin…

Mitigation only
Fix from $1,600 2026-05-22
Concrete Cms MEDIUM 5.4
CVE-2026-8139

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Taxonomy Term Reference Tree Widget MEDIUM 5.4
CVE-2026-4093

In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templat…

Fix: 7.x-1.12+
Fix from $1,600 2026-05-21
Simple Hierarchical Select MEDIUM 5.4
CVE-2026-4929

Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affe…

Fix: after 7.x-1.10
Fix from $1,600 2026-05-21
Webmin MEDIUM 5.4
CVE-2026-22678

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status modu…

Fix: 2.641+
Fix from $1,600 2026-05-21
Concrete Cms MEDIUM 5.4
CVE-2026-8203

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privi…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48225

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject ar…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48226

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48227

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject …

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48228

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to injec…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48229

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48230

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that allows authenticated attackers …

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48218

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that allows authenticated attacker…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48219

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48220

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48221

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject …

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48222

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48223

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48224

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48214

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48215

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject a…

Patch available
Fix from $1,600 2026-05-21