Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 8.7
CVE-2026-72730

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controll…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.4
CVE-2026-72720

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in Pretty…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that …

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-72751

CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX cont…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML p…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-18478

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name o…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.6
CVE-2026-72594

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72583

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file cont…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72576

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary J…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72570

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into t…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.8
CVE-2026-57279

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web brows…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-17010

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing user…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.1
CVE-2026-17019

The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.8
CVE-2026-14293

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and do…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.8
CVE-2026-15047

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, all…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.1
CVE-2026-16032

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before stori…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.1
CVE-2026-71502

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in ser…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthentic…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and do…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload b…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.4
CVE-2026-18988

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, a…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.7
CVE-2026-48026

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.8…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.0
CVE-2026-62293

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command con…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.9
CVE-2026-64638

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hoste…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-17596

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:updat…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-48093

The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in p…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-66494

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-48094

The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-54216

Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted l…

No fix yet
Fix from $1,600 2026-08-07