Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-6237

The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions u…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-6247

The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortco…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-6256

The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all ve…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 7.2
CVE-2026-6690

The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all version…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-4859

The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortc…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-4920

The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-5340

The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.4
CVE-2026-2300

The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.1
CVE-2026-40137

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect…

Mitigation only
Fix from $1,600 2026-05-12
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-27682

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.7
CVE-2026-45392

DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an auth…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-43900

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Script…

Mitigation only
Fix from $2,300 2026-05-11
Fiber MEDIUM 6.1
CVE-2026-42554

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitr…

Fix: 2.52.12 / 3.1.0+
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2026-43887

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other us…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.1
CVE-2026-43878

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the attacker-controlled user and pa…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.4
CVE-2026-43876

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST par…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.8
CVE-2026-45026

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authentic…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.8
CVE-2026-45025

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authentic…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.4
CVE-2026-42870

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the follow…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2026-42872

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-7308

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of a…

Mitigation only
Fix from $1,600 2026-05-11
Openedx MEDIUM 5.4
CVE-2026-42857

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion…

Fix: 2026-04-24+
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.4
CVE-2026-38569

HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.7
CVE-2026-41250

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.2
CVE-2026-44737

grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modif…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.4
CVE-2026-42842

The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Gr…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2026-36906

Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function

Mitigation only
Fix from $1,600 2026-05-11
Grav HIGH 8.9
CVE-2026-42611

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection …

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Grav MEDIUM 5.4
CVE-2026-42612

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level ac…

Fix: after 1.8.0
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-3320

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in th…

Mitigation only
Fix from $1,600 2026-05-11