Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2022-50946

WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malici…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2022-50947

WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inje…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2022-50948

Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scrip…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2022-50949

WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious s…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47947

Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting …

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47950

Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated a…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47951

WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts …

No fix yet
Fix from $1,600 2026-05-10
Moodle MEDIUM 6.1
CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads…

Fix: after 4.0.0
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47929

Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScr…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47931

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Tit…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47922

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts throug…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47924

Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47925

CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTM…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47926

Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by …

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47927

WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject maliciou…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47907

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malici…

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.4
CVE-2021-47910

AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts b…

No fix yet
Fix from $1,600 2026-05-10
PHP MEDIUM 6.1
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows…

Fix: 8.2.31 / 8.3.31+
Fix from $1,600 2026-05-10
Unclassified HIGH 8.8
CVE-2026-42455

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In versions 2.14.0 and prior, the …

Mitigation only
Fix from $1,950 2026-05-09
Postiz CRITICAL 9.0
CVE-2026-42556

Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store ar…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-42451

Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimmory's browser-based EPUB…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.6
CVE-2026-42224

ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malic…

Patch available
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.4
CVE-2026-42192

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in t…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.5
CVE-2026-41886

locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK registers a window.addEventListen…

Mitigation only
Fix from $1,950 2026-05-08
Absinthe.plug MEDIUM 6.1
CVE-2026-42794

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripti…

Fix: 1.5.10+
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.4
CVE-2026-41591

Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dyna…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 8.6
CVE-2026-41683

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 8.7
CVE-2026-41524

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verba…

Patch available
Fix from $1,950 2026-05-08
W4nn4d13\/ip MEDIUM 6.1
CVE-2026-41575

In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Che…

Fix: 2.0.1+
Fix from $1,600 2026-05-08
Unclassified HIGH 7.1
CVE-2026-41576

Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication required). User-supplied message…

Patch available
Fix from $1,950 2026-05-08