Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 5.4
CVE-2026-40212

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is us…

Mitigation only
Fix from $1,600 2026-04-10
Lollms CRITICAL 9.6
CVE-2026-1115

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.…

Fix: after 2.1.0
Fix from $2,300 2026-04-10
Unclassified MEDIUM 6.4
CVE-2026-2305

The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `a…

Mitigation only
Fix from $1,600 2026-04-10
Unclassified MEDIUM 6.1
CVE-2026-4305

The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' param…

Mitigation only
Fix from $1,600 2026-04-10
Unclassified MEDIUM 6.4
CVE-2026-1263

The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input s…

Mitigation only
Fix from $1,600 2026-04-10
Praisonai MEDIUM 6.1
CVE-2026-40112

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effect…

Fix: 4.5.128+
Fix from $1,600 2026-04-09
Junos Space MEDIUM 6.1
CVE-2026-21904

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attac…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54364

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by ma…

No fix yet
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54360

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating th…

No fix yet
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54361

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manip…

No fix yet
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54362

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by m…

No fix yet
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54363

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by m…

No fix yet
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2023-54358

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious…

No fix yet
Fix from $1,600 2026-04-09
Limesurvey MEDIUM 6.1
CVE-2025-63238

A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInst…

Fix: 6.15.12+
Fix from $1,600 2026-04-09
Limesurvey MEDIUM 6.1
CVE-2025-70797

Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] …

Patch available
Fix from $1,600 2026-04-09
Churchcrm MEDIUM 6.1
CVE-2026-39941

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and ED…

Fix: 7.1.0+
Fix from $1,600 2026-04-09
Unclassified MEDIUM 5.4
CVE-2025-70365

A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.1
CVE-2025-45806

A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrary web scripts or HTML via a c…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.4
CVE-2026-3005

The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to,…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.4
CVE-2026-5742

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient inp…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.4
CVE-2026-4336

The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.4
CVE-2026-4429

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attri…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 6.4
CVE-2026-5357

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in ver…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified MEDIUM 5.1
CVE-2026-3438

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote a…

Mitigation only
Fix from $1,600 2026-04-08
GitLab MEDIUM 5.4
CVE-2026-4332

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in cus…

Fix: 18.8.9 / 18.9.5+
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-5711

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider b…

Mitigation only
Fix from $1,600 2026-04-08
Hayabusa MEDIUM 5.4
CVE-2026-40028

Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allows an attacker to execute arbi…

Fix: 3.8.0+
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-5451

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions …

No fix yet
Fix from $1,600 2026-04-08
Ail Framework MEDIUM 6.1
CVE-2026-39416

AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) …

Fix: after 6.7
Fix from $1,600 2026-04-08
Immich MEDIUM 5.4
CVE-2026-35455

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama…

Fix: 2.7.0+
Fix from $1,600 2026-04-08