Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Loris MEDIUM 5.4
CVE-2026-35169

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: after 27.0.2
Fix from $1,600 2026-04-08
Loris MEDIUM 5.4
CVE-2026-35403

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: after 27.0.2
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-2509

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all …

Mitigation only
Fix from $1,600 2026-04-08
Coolercontrold MEDIUM 6.1
CVE-2026-5301

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript …

Fix: 4.0.0+
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-2481

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[j…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4303

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wsm_showDayStatsGra…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4073

The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions up to, and including, 1.0.5.…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4300

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4025

The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attribute in the [pc-login-form] …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39708

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uicore UiCore Elements uicore-elements allows S…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39696

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-wha…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39702

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wealcoder Animation Addons for Elementor animat…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39703

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39692

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Store…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39693

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fesomia FSM Custom Featured Image Caption fsm-c…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39683

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chief Gnome Garden Gnome Package garden-gnome-p…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39667

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-B…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39674

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distanc…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39665

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39666

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allo…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39654

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-h…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39646

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaflet-map allows Stored XS…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39636

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-f…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39638

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This is…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39615

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allo…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39604

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable all…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39575

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-ar…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.9
CVE-2026-39541

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Sto…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39517

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Ba…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39500

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor them…

Mitigation only
Fix from $1,600 2026-04-08