Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Chrome MEDIUM 5.4
CVE-2026-7939

Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (U…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Unclassified MEDIUM 5.4
CVE-2026-36358

Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner …

Mitigation only
Fix from $1,600 2026-05-06
Dfxanalytics MEDIUM 6.1
CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection …

Fix: 4.1+
Fix from $1,600 2026-05-06
Dfxanalytics MEDIUM 6.1
CVE-2025-31970

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict dire…

Fix: 4.1+
Fix from $1,600 2026-05-06
Wicket MEDIUM 6.1
CVE-2026-42509

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
Unclassified HIGH 7.2
CVE-2026-7332

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookin…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified MEDIUM 6.4
CVE-2026-7457

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficien…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified HIGH 7.3
CVE-2026-23928

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This …

Mitigation only
Fix from $1,950 2026-05-06
Unclassified MEDIUM 6.4
CVE-2026-6672

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all ve…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified HIGH 7.3
CVE-2026-23926

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip …

Mitigation only
Fix from $1,950 2026-05-06
Phpspreadsheet MEDIUM 5.4
CVE-2026-35453

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3…

Fix: 1.30.4 / 2.1.16+
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.1
CVE-2026-38947

FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.

No fix yet
Fix from $1,600 2026-05-05
Erpnext MEDIUM 6.1
CVE-2026-38432

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit …

Fix: after 15.103.1
Fix from $1,600 2026-05-05
Traccar MEDIUM 5.4
CVE-2026-27694

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates ins…

Fix: 6.13.0+
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.1
CVE-2023-54349

AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitt…

No fix yet
Fix from $1,600 2026-05-05
Unclassified HIGH 7.2
CVE-2026-4803

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-5159

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_te…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-4665

The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.1
CVE-2026-6704

The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-5505

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-6255

The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode i…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.1
CVE-2026-6696

The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_name', 'last_name', and 'phone…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-2868

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separato…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 6.4
CVE-2026-4730

The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerable to Stored Cross-Site Script…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified MEDIUM 5.5
CVE-2026-5247

The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of t…

Mitigation only
Fix from $1,600 2026-05-05
N8n CRITICAL 9.6
CVE-2026-42235

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a mali…

Fix: 1.123.32 / 2.17.4+
Fix from $2,300 2026-05-04
Dify MEDIUM 6.1
CVE-2026-42138

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can u…

Fix: 1.13.1+
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.0
CVE-2026-42052

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for …

Mitigation only
Fix from $1,600 2026-05-04
Notesnook Desktop CRITICAL 9.6
CVE-2026-42090

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi…

Fix: 3.3.15 / 3.3.20+
Fix from $2,300 2026-05-04
Unclassified MEDIUM 6.1
CVE-2026-38669

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

Mitigation only
Fix from $1,600 2026-05-04