Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-4005

The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up t…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.4
CVE-2026-4011

The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions …

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 7.2
CVE-2026-3643

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The pl…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 8.9
CVE-2025-40899

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An…

Mitigation only
Fix from $1,950 2026-04-15
Goldmark MEDIUM 6.1
CVE-2026-5160

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of…

Fix: 1.7.17+
Fix from $1,600 2026-04-15
Unclassified MEDIUM 5.4
CVE-2026-26291

Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed…

Mitigation only
Fix from $1,600 2026-04-15
Immich MEDIUM 5.4
CVE-2026-40096

immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the s…

Fix: 2.7.3+
Fix from $1,600 2026-04-15
Unclassified HIGH 7.2
CVE-2026-2834

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description…

Mitigation only
Fix from $1,950 2026-04-15
Docmost MEDIUM 5.4
CVE-2026-34212

Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docm…

Fix: 0.71.0+
Fix from $1,600 2026-04-14
Chamilo Lms MEDIUM 5.4
CVE-2026-34161

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists i…

Fix: after 1.11.38
Fix from $1,600 2026-04-14
Experience Manager MEDIUM 5.4
CVE-2026-34624

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could …

Fix: 6.5.11.8+
Fix from $1,600 2026-04-14
Experience Manager MEDIUM 5.4
CVE-2026-34625

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could …

Fix: 6.5.11.8+
Fix from $1,600 2026-04-14
Experience Manager MEDIUM 5.4
CVE-2026-34623

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could …

Fix: 6.5.11.8+
Fix from $1,600 2026-04-14
Connect MEDIUM 6.1
CVE-2026-34614

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to conv…

Fix: 12.11 / 2025.9.15+
Fix from $1,600 2026-04-14
Connect HIGH 8.7
CVE-2026-34617

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation…

Fix: 12.11 / 2025.9.15+
Fix from $1,950 2026-04-14
Windows Admin Center MEDIUM 6.1
CVE-2026-32196

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo…

Fix: 2511+
Fix from $1,600 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27246

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Experience Manager MEDIUM 5.4
CVE-2026-27288

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could …

Fix: 6.5.11.8+
Fix from $1,600 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27243

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27245

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
October MEDIUM 5.4
CVE-2026-24906

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulner…

Fix: after 4.1.9
Fix from $1,600 2026-04-14
October MEDIUM 5.4
CVE-2026-24907

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulner…

Fix: after 4.1.9
Fix from $1,600 2026-04-14
Sharepoint Server MEDIUM 5.4
CVE-2026-20945EPSS 25%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
Connect MEDIUM 6.1
CVE-2026-21331

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to conv…

Fix: 12.11 / 2025.9.15+
Fix from $1,600 2026-04-14
Fortisoar MEDIUM 5.4
CVE-2026-22154

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3,…

Fix: 7.5.3 / 7.6.4+
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.1
CVE-2025-65134

In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.1
CVE-2025-65136

In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.

Mitigation only
Fix from $1,600 2026-04-14
Unclassified MEDIUM 6.1
CVE-2025-65132

alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject a…

Mitigation only
Fix from $1,600 2026-04-14
Fortisandbox MEDIUM 5.4
CVE-2025-61886

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…

Fix: 5.0.5+
Fix from $1,600 2026-04-14
Unclassified MEDIUM 5.4
CVE-2026-4914

Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User…

Mitigation only
Fix from $1,600 2026-04-14