Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Helpy MEDIUM 5.4
CVE-2026-40229

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their …

No fix yet
Fix from $1,600 2026-04-29
Helpy MEDIUM 5.4
CVE-2026-40230

Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent e…

No fix yet
Fix from $1,600 2026-04-29
Opennebula MEDIUM 6.1
CVE-2025-56534

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scrip…

Fix: 7.0.0+
Fix from $1,600 2026-04-29
Opennebula MEDIUM 6.1
CVE-2025-56535

A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted …

Fix: 7.0.0+
Fix from $1,600 2026-04-29
Opennebula MEDIUM 6.1
CVE-2025-56536

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a c…

Fix: 7.0.0+
Fix from $1,600 2026-04-29
Opennebula MEDIUM 6.1
CVE-2025-56537

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTM…

Fix: 7.0.0+
Fix from $1,600 2026-04-29
GitHub CRITICAL 9.0
CVE-2026-42523

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHu…

Fix: 1.46.0.1+
Fix from $2,300 2026-04-29
Html Publisher HIGH 8.0
CVE-2026-42524

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting…

Fix: after 427
Fix from $1,950 2026-04-29
Unclassified HIGH 7.1
CVE-2026-42652

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration a…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified MEDIUM 5.9
CVE-2026-42643

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stor…

Mitigation only
Fix from $1,600 2026-04-29
Unclassified MEDIUM 6.1
CVE-2026-2902

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frontend_rewrite' function'…

Mitigation only
Fix from $1,600 2026-04-29
Identity Server MEDIUM 6.1
CVE-2025-10503

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encodin…

Fix: 7.1.0.28+
Fix from $1,600 2026-04-29
Unclassified HIGH 7.2
CVE-2026-42615

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

Patch available
Fix from $1,950 2026-04-29
Unclassified MEDIUM 6.1
CVE-2026-37750

A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arb…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified HIGH 8.9
CVE-2026-38949

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint.…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.4
CVE-2026-38948

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properl…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.4
CVE-2026-4805

The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient in…

Patch available
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.4
CVE-2026-6551

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-bloc…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.4
CVE-2026-6725

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.4
CVE-2026-6809

The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-04-28
Pimcore MEDIUM 5.4
CVE-2026-5362

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script ex…

No fix yet
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.1
CVE-2026-29971

A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled input is refle…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.1
CVE-2026-38935

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.1
CVE-2026-38936

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.4
CVE-2026-41467

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileNa…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.4
CVE-2026-41466

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php th…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.5
CVE-2026-42410

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elemento…

Mitigation only
Fix from $1,600 2026-04-27
Cyberpanel MEDIUM 6.1
CVE-2026-41472

CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/cal…

Fix: 2.4.4+
Fix from $1,600 2026-04-24
Pretalx MEDIUM 6.1
CVE-2026-41426

pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance…

Fix: 2026.1.0+
Fix from $1,600 2026-04-24
Unclassified HIGH 8.8
CVE-2026-41421

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Ele…

Mitigation only
Fix from $1,950 2026-04-24