Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.4
CVE-2026-48216

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to injec…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48217

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to i…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-48213

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbi…

Patch available
Fix from $1,600 2026-05-21
Request Tracker MEDIUM 6.1
CVE-2026-6841

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft…

Fix: 5.0.10 / 6.0.3+
Fix from $1,600 2026-05-21
Unclassified MEDIUM 6.4
CVE-2026-1543

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.4
CVE-2026-39960

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a text…

Patch available
Fix from $1,600 2026-05-20
Unclassified HIGH 7.6
CVE-2026-9144

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-47099

TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary Ja…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.8
CVE-2026-39311

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prio…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-26028

CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed du…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-30691

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified HIGH 7.2
CVE-2026-7613

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parame…

Mitigation only
Fix from $1,950 2026-05-20
Infoscale Operations Manager MEDIUM 5.4
CVE-2026-44924

InfoScale VIOM 9.1.3 allows XSS.

Fix: 9.1.3+
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.3
CVE-2026-4293

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's brow…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified HIGH 7.6
CVE-2026-5783

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Tra…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.5
CVE-2026-24573

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This i…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.4
CVE-2026-2955

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in ve…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified HIGH 7.4
CVE-2026-7460

mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entr…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-8624

The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, a…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-8626

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-8627

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and i…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-7462

The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.4
CVE-2026-8038

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shor…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.4
CVE-2026-6549

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.4
CVE-2026-5293

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in …

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.4
CVE-2026-6397

The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up …

Mitigation only
Fix from $1,600 2026-05-20
Drupal MEDIUM 6.1
CVE-2026-6365

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.5.9 / 10.6.7+
Fix from $1,600 2026-05-19
Drupal MEDIUM 6.1
CVE-2026-6367

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 11.3.7+
Fix from $1,600 2026-05-19
Obfuscate MEDIUM 6.1
CVE-2026-6871

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (X…

Fix: 2.0.2+
Fix from $1,600 2026-05-19
Colorbox Inline MEDIUM 5.4
CVE-2026-8493

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Script…

Fix: 2.1.1+
Fix from $1,600 2026-05-19