Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.1
CVE-2026-3319

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in th…

Mitigation only
Fix from $1,600 2026-05-11
Scribunto HIGH 7.5
CVE-2026-34089

Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.

Fix: 1.45.2+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-65417

docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61308

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61309

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61310

A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2025-61311

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c all…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2025-61312

A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c al…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2025-61313

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.1…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2025-61314

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61305

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61306

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2025-61307

A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c all…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-6909

ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-6956

ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.1
CVE-2022-50963

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_fro…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50964

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50965

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and creat…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50966

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and create…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50967

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and cre…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50968

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and cr…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50969

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 5.4
CVE-2022-50970

WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by…

No fix yet
Fix from $1,600 2026-05-10
Avatar Uploader MEDIUM 6.1
CVE-2022-50957

Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject maliciou…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50958

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50959

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject maliciou…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50960

WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter …

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2022-50961

WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject ar…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.1
CVE-2022-50962

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and cr…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2022-50945

WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal…

No fix yet
Fix from $1,600 2026-05-10