Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Astro MEDIUM 6.1
CVE-2026-41067

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/scr…

Fix: 6.1.6+
Fix from $1,600 2026-04-24
Unclassified MEDIUM 6.1
CVE-2025-61872

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the …

Mitigation only
Fix from $1,600 2026-04-24
Activemq MEDIUM 6.5
CVE-2026-41043

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate…

Fix: 5.19.6 / 6.2.5+
Fix from $1,600 2026-04-24
Unclassified MEDIUM 6.4
CVE-2026-4078

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-…

Mitigation only
Fix from $1,600 2026-04-24
Unclassified MEDIUM 6.4
CVE-2026-5428

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel wid…

Mitigation only
Fix from $1,600 2026-04-24
Press MEDIUM 6.1
CVE-2026-41430

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect para…

Fix: 0.16.0+
Fix from $1,600 2026-04-24
Anythingllm MEDIUM 5.4
CVE-2026-41318

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, …

Fix: 1.12.1+
Fix from $1,600 2026-04-24
Unclassified MEDIUM 6.1
CVE-2026-41305

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior t…

Mitigation only
Fix from $1,600 2026-04-24
Xibo MEDIUM 5.4
CVE-2026-31953

Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripti…

Fix: 4.4.1+
Fix from $1,600 2026-04-24
Pretalx MEDIUM 5.4
CVE-2026-41241

pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display nam…

Fix: 2026.1.0+
Fix from $1,600 2026-04-23
Unclassified MEDIUM 6.9
CVE-2026-41238

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollutio…

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 6.8
CVE-2026-41239

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TE…

Mitigation only
Fix from $1,600 2026-04-23
Dompurify MEDIUM 6.1
CVE-2026-41240

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS a…

Fix: 3.4.0+
Fix from $1,600 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-40470

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the docum…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-40472

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cro…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified MEDIUM 6.5
CVE-2025-62110

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored X…

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 6.5
CVE-2026-28040

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCom…

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 6.4
CVE-2026-3361

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and …

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 5.4
CVE-2026-3007

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user ac…

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 5.4
CVE-2026-2951

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up …

Mitigation only
Fix from $1,600 2026-04-23
Unclassified HIGH 8.5
CVE-2026-41200

STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.…

Mitigation only
Fix from $1,950 2026-04-23
Unclassified MEDIUM 6.4
CVE-2026-1923

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up…

Mitigation only
Fix from $1,600 2026-04-23
Frappe MEDIUM 5.4
CVE-2026-3837

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the aff…

Patch available
Fix from $1,600 2026-04-22
Frappe MEDIUM 5.4
CVE-2026-3673

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where…

No fix yet
Fix from $1,600 2026-04-22
GitLab MEDIUM 6.1
CVE-2026-5262

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that …

Fix: 18.9.6 / 18.10.4+
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.1
CVE-2026-30139

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to …

Patch available
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2024-58344

Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript c…

No fix yet
Fix from $1,600 2026-04-22
Icewarp MEDIUM 6.1
CVE-2018-25269

ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embe…

No fix yet
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-1395

The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id attribute in all versions up to…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-1913

The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_link shortcode in all versions …

Mitigation only
Fix from $1,600 2026-04-22