Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-6246

The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the …

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4279

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versio…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4353

The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in al…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-5748

The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-5767

The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up …

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-5820

The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4125

The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and includ…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4076

The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attribute…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4082

The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4085

The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the '…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4088

The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4089

The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and i…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.4
CVE-2026-4074

The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in al…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 5.5
CVE-2026-1845

The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 …

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.1
CVE-2026-40451

DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute ar…

Mitigation only
Fix from $1,600 2026-04-22
Avideo MEDIUM 5.4
CVE-2026-41061

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-41063

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides …

Fix: after 29.0
Fix from $1,600 2026-04-21
Docmost MEDIUM 5.4
CVE-2026-40927

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a …

Fix: 0.80.0+
Fix from $1,600 2026-04-21
Unclassified HIGH 7.0
CVE-2026-40875

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful con…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.3
CVE-2026-40872

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs r…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified HIGH 8.9
CVE-2026-40873

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects atta…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.1
CVE-2026-41456

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers…

Patch available
Fix from $1,600 2026-04-21
Unclassified HIGH 8.5
CVE-2026-40568

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the…

Patch available
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.7
CVE-2026-35451

Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a l…

Patch available
Fix from $1,600 2026-04-21
Freescout MEDIUM 6.1
CVE-2026-40565

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php convert…

Fix: 1.8.213+
Fix from $1,600 2026-04-21
Php Point Of Sale MEDIUM 6.1
CVE-2025-41011

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack o…

Mitigation only
Fix from $1,600 2026-04-21
Ad Phonebook MEDIUM 6.1
CVE-2026-31013

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Depart…

Fix: 4.0.1.1+
Fix from $1,600 2026-04-21
Unclassified MEDIUM 5.1
CVE-2025-10354

Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the vic…

Mitigation only
Fix from $1,600 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6779

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Unclassified MEDIUM 5.1
CVE-2026-3317

Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint becaus…

Mitigation only
Fix from $1,600 2026-04-21