Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.1
CVE-2026-6711

The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-04-21
Freescout HIGH 8.1
CVE-2026-40497

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`…

Fix: 1.8.213+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.4
CVE-2026-4852

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Sour…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-39112

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visi…

Mitigation only
Fix from $1,600 2026-04-20
Helpdesk MEDIUM 5.4
CVE-2026-23756

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not …

Fix: 4.99.9+
Fix from $1,600 2026-04-20
Helpdesk MEDIUM 5.4
CVE-2026-23757

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly t…

Fix: 4.99.10+
Fix from $1,600 2026-04-20
Helpdesk MEDIUM 5.4
CVE-2026-23758

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members t…

Fix: 4.99.9+
Fix from $1,600 2026-04-20
Unclassified MEDIUM 5.4
CVE-2026-34429

Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions …

Patch available
Fix from $1,600 2026-04-20
Sd 330ac Firmware MEDIUM 6.1
CVE-2026-32963

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affect…

Fix: 1.50 / 5.1.0+
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.4
CVE-2026-0868

The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly short…

Mitigation only
Fix from $1,600 2026-04-19
Unclassified MEDIUM 6.4
CVE-2026-2986

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.4
CVE-2026-0894

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 5.4
CVE-2026-2505

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.4
CVE-2026-6048

The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attribu…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.4
CVE-2026-4801

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all ver…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.4
CVE-2026-1559

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.1
CVE-2026-1838

The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including…

Mitigation only
Fix from $1,600 2026-04-18
Postiz CRITICAL 9.0
CVE-2026-40487

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr…

Fix: 2.21.6+
Fix from $2,300 2026-04-18
Unclassified MEDIUM 5.4
CVE-2026-40483

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTM…

Patch available
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.4
CVE-2026-2434

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and …

Mitigation only
Fix from $1,600 2026-04-17
Kimai MEDIUM 5.4
CVE-2026-40479

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape …

Fix: 2.53.0+
Fix from $1,600 2026-04-17
Wger MEDIUM 5.4
CVE-2026-40353

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs …

Fix: 2.5+
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.4
CVE-2026-40282

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti…

No fix yet
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.8
CVE-2026-40284

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified HIGH 7.5
CVE-2026-40286

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in …

Mitigation only
Fix from $1,950 2026-04-17
Zrok MEDIUM 6.1
CVE-2026-40302

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template …

Fix: 2.0.1+
Fix from $1,600 2026-04-17
Stirling Pdf MEDIUM 6.1
CVE-2026-33436

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints …

Fix: 2.0.0+
Fix from $1,600 2026-04-17
Wegia HIGH 7.6
CVE-2026-40283

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti…

Fix: 3.6.10+
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.4
CVE-2026-5162

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_te…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified HIGH 7.2
CVE-2026-5231

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includi…

Mitigation only
Fix from $1,950 2026-04-17