Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-7475

The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to,…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.4
CVE-2026-7650

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-down…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.4
CVE-2026-5341

The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all ve…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.2
CVE-2026-7330

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to ins…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.4
CVE-2024-33724

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.1
CVE-2023-42343

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.1
CVE-2023-42345

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.1
CVE-2022-23961

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthen…

Mitigation only
Fix from $1,600 2026-05-08
Enterprise Server MEDIUM 6.1
CVE-2026-8106

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential the…

Fix: 3.19.6 / 3.20.2+
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.1
CVE-2026-41929

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attac…

Patch available
Fix from $1,600 2026-05-07
Azure Machine Learning MEDIUM 6.1
CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…

Mitigation only
Fix from $1,600 2026-05-07
Go MEDIUM 6.1
CVE-2026-39823

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were t…

Fix: 1.25.10 / 1.26.3+
Fix from $1,600 2026-05-07
Postorius MEDIUM 6.1
CVE-2026-44742

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2…

Fix: after 1.3.13
Fix from $1,600 2026-05-07
Unclassified HIGH 7.6
CVE-2026-41904

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission c…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 7.0
CVE-2026-41653

BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. …

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.4
CVE-2026-36388

A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This f…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 5.4
CVE-2026-36341

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment fie…

Patch available
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.1
CVE-2025-67202

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL be…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified HIGH 7.1
CVE-2026-41554

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issu…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 8.8
CVE-2026-5784

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…

Mitigation only
Fix from $1,950 2026-05-07
Misp MEDIUM 5.4
CVE-2026-8080

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue…

Fix: 2.5.37+
Fix from $1,600 2026-05-07
Unclassified HIGH 8.8
CVE-2026-3953

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Pro…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 6.5
CVE-2026-27421

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XS…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 5.9
CVE-2025-62127

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.1
CVE-2026-41661

Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admid…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified CRITICAL 9.1
CVE-2026-41201

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In vers…

Mitigation only
Fix from $2,300 2026-05-07
Phpspreadsheet MEDIUM 5.4
CVE-2026-40296

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatt…

Fix: 1.30.4 / 2.1.16+
Fix from $1,600 2026-05-06
Unclassified HIGH 8.4
CVE-2026-40171

In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @…

Mitigation only
Fix from $1,950 2026-05-06
Chrome MEDIUM 5.4
CVE-2026-8012

Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to i…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Chrome MEDIUM 5.4
CVE-2026-7958

Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06