Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.7
CVE-2026-31205

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanit…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified CRITICAL 9.8
CVE-2025-14320

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Tra…

Mitigation only
Fix from $2,300 2026-05-04
Gv Lpc2011 Firmware MEDIUM 6.1
CVE-2026-7371

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A…

Mitigation only
Fix from $1,600 2026-05-04
Gv Lpc2011 Firmware MEDIUM 6.1
CVE-2026-42366

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.2
CVE-2026-5063

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in…

Mitigation only
Fix from $1,950 2026-05-03
Unclassified MEDIUM 6.4
CVE-2026-0703

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 5.8
CVE-2026-6817

The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 5.4
CVE-2026-4790

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 5.4
CVE-2026-5077

The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficien…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5324

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2.8.…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5113

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2…

No fix yet
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.4
CVE-2026-6916

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site …

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5109

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficie…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5110

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is d…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5111

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficie…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.2
CVE-2026-5112

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is d…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.4
CVE-2026-4658

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.4
CVE-2026-7209

The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versi…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.4
CVE-2026-6378

The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in…

Patch available
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.1
CVE-2025-69606

Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/erro…

Mitigation only
Fix from $1,600 2026-05-01
Unclassified MEDIUM 5.4
CVE-2026-40201

@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.

Patch available
Fix from $1,600 2026-05-01
Unclassified MEDIUM 6.4
CVE-2026-6127

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to,…

No fix yet
Fix from $1,600 2026-05-01
Unclassified MEDIUM 6.1
CVE-2024-13362

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insuff…

Mitigation only
Fix from $1,600 2026-05-01
Unclassified MEDIUM 6.1
CVE-2026-36761

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scr…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified MEDIUM 6.1
CVE-2026-36763

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arb…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified MEDIUM 5.4
CVE-2026-36766

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to ex…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified MEDIUM 6.1
CVE-2026-38939

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive informa…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified MEDIUM 6.1
CVE-2026-38940

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php com…

Mitigation only
Fix from $1,600 2026-04-30
Lex Baza Dokumentow MEDIUM 5.4
CVE-2026-1493

LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, all…

Fix: 1.3.4+
Fix from $1,600 2026-04-30
Recent Threads On Index MEDIUM 6.1
CVE-2018-25309

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threa…

No fix yet
Fix from $1,600 2026-04-29