Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Siyuan MEDIUM 5.4
CVE-2026-40922

SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incom…

Fix: 3.6.4+
Fix from $1,600 2026-04-17
Unclassified HIGH 8.7
CVE-2026-40262

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies…

Patch available
Fix from $1,950 2026-04-17
Siyuan CRITICAL 9.0
CVE-2026-40322

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "…

Fix: 3.6.4+
Fix from $2,300 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-2840

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' …

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 5.4
CVE-2026-3369

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in ve…

Mitigation only
Fix from $1,600 2026-04-16
Api Manager MEDIUM 6.1
CVE-2025-6024

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can l…

Mitigation only
Fix from $1,600 2026-04-16
Api Manager MEDIUM 5.4
CVE-2024-4867

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This d…

Fix: 3.2.0.408 / 3.2.1.32+
Fix from $1,600 2026-04-16
Api Manager MEDIUM 6.1
CVE-2024-10242

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to in…

Fix: 3.2.0.401 / 4.0.0.318+
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-3875

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, …

Mitigation only
Fix from $1,600 2026-04-16
Unclassified HIGH 7.2
CVE-2026-3876

The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, a…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-1572

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin …

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.1
CVE-2026-3355

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all version…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2025-13364

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scri…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-5070

The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.1
CVE-2026-4032

The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up …

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-3878

The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parameter in all versions up to, an…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-3885

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode …

Mitigation only
Fix from $1,600 2026-04-16
Unclassified MEDIUM 6.4
CVE-2026-3299

The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-04-16
Prometheus MEDIUM 6.1
CVE-2026-40179

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site s…

Fix: 3.5.2 / 3.11.2+
Fix from $1,600 2026-04-15
Apostrophecms MEDIUM 6.1
CVE-2026-40186

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the Apos…

Fix: after 2.17.1
Fix from $1,600 2026-04-15
Apostrophecms HIGH 8.7
CVE-2026-35569

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in S…

Fix: 4.29.0+
Fix from $1,950 2026-04-15
Apostrophecms MEDIUM 5.4
CVE-2026-33889

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in t…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.9
CVE-2026-6370

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Ajax Cart for WooCommerce allow…

Mitigation only
Fix from $1,600 2026-04-15
Unity Connection MEDIUM 6.1
CVE-2026-20059

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflecte…

Fix: after 12.5
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.5
CVE-2025-15636

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design YouTube Showcase youtube-showcas…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.5
CVE-2026-40734

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories Images categories-images allo…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 7.2
CVE-2026-5694

The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified MEDIUM 6.4
CVE-2026-5717

The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.4
CVE-2026-3659

The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [circliful] shortcode and …

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.4
CVE-2026-3998

The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of the [jqmath] shortcode in all …

Mitigation only
Fix from $1,600 2026-04-15