Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Orejime MEDIUM 6.1
CVE-2026-6095

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS…

Fix: 2.0.16+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.1
CVE-2026-5090

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quo…

Patch available
Fix from $1,600 2026-05-19
Unclassified HIGH 8.7
CVE-2026-34241

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability i…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 8.6
CVE-2026-34463

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue or…

Patch available
Fix from $1,950 2026-05-19
Unclassified MEDIUM 6.8
CVE-2026-33741

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments …

Mitigation only
Fix from $1,600 2026-05-19
Firefox CRITICAL 9.1
CVE-2026-8948

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $2,300 2026-05-19
Cmc MEDIUM 5.4
CVE-2025-40904

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenti…

Fix: 26.1.0+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31906

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-27737

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user'…

Patch available
Fix from $1,600 2026-05-18
Unclassified MEDIUM 6.1
CVE-2026-45231

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber…

Patch available
Fix from $1,600 2026-05-18
Edge Chromium MEDIUM 6.1
CVE-2026-45494

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 148.0.3967.70+
Fix from $1,600 2026-05-18
Mailinspector MEDIUM 6.1
CVE-2026-29964

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-co…

Mitigation only
Fix from $1,600 2026-05-18
Mailinspector MEDIUM 6.1
CVE-2026-29965

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of us…

Mitigation only
Fix from $1,600 2026-05-18
Unclassified HIGH 8.8
CVE-2026-7498

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and O…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 8.8
CVE-2026-3220

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vuln…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 7.1
CVE-2026-6495

The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified MEDIUM 6.1
CVE-2018-25331

Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by ma…

No fix yet
Fix from $1,600 2026-05-17
Unclassified MEDIUM 5.4
CVE-2021-47981

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by su…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2021-47957

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitti…

No fix yet
Fix from $1,600 2026-05-16
Unclassified HIGH 7.2
CVE-2021-47975

WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through…

No fix yet
Fix from $1,950 2026-05-16
Unclassified MEDIUM 5.3
CVE-2021-47934

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post c…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 5.4
CVE-2021-47955

CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicio…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37240

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scrip…

No fix yet
Fix from $1,600 2026-05-16
Unclassified HIGH 7.5
CVE-2020-37245

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside …

No fix yet
Fix from $1,950 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37233

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privile…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37235

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject mal…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37236

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scrip…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37237

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts thr…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.4
CVE-2020-37238

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject mal…

No fix yet
Fix from $1,600 2026-05-16