Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.5
CVE-2026-39508

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39482

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allo…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39483

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-1396

The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4655

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to an…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-5506

The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-5508

The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4871

The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' attributes of the `scm_memb…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3618

The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [print_clmns] sh…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3142

The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_var' parameter …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2025-1794

The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.…

Mitigation only
Fix from $1,600 2026-04-08
Matcha Sns MEDIUM 5.4
CVE-2026-27787

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on…

Fix: after 1.3.9
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3311

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Store…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4333

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_c…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4341

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mou…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4785

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3239

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3513

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode i…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-3600

The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-year…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-4379

The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in a…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.4
CVE-2026-2988

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up…

Mitigation only
Fix from $1,600 2026-04-08
Go MEDIUM 6.1
CVE-2026-32289

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches w…

Fix: 1.25.9 / 1.26.2+
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.1
CVE-2026-4394

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.9
CVE-2026-39935

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEv…

Mitigation only
Fix from $1,600 2026-04-07
Unclassified MEDIUM 6.9
CVE-2026-39936

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Exte…

Mitigation only
Fix from $1,600 2026-04-07
Siyuan CRITICAL 9.0
CVE-2026-39846

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si…

Fix: 3.6.4+
Fix from $2,300 2026-04-07
Unclassified MEDIUM 6.9
CVE-2026-39933

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatc…

Mitigation only
Fix from $1,600 2026-04-07
Cronicle MEDIUM 6.1
CVE-2026-39400

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_ev…

Fix: 0.9.111+
Fix from $1,600 2026-04-07
Open Source Point Of Sale MEDIUM 5.4
CVE-2026-32712

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc…

Fix: 3.4.3+
Fix from $1,600 2026-04-07
Cargo MEDIUM 6.1
CVE-2026-39841

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allow…

Fix: 3.8.7+
Fix from $1,600 2026-04-07