Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.9
CVE-2026-39838

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage …

Mitigation only
Fix from $1,600 2026-04-07
Cargo MEDIUM 6.1
CVE-2026-39840

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extensio…

Fix: 3.8.7+
Fix from $1,600 2026-04-07
Open Source Point Of Sale MEDIUM 5.4
CVE-2026-39380

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc…

Fix: 3.4.3+
Fix from $1,600 2026-04-07
Avideo MEDIUM 5.4
CVE-2026-39367

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-contro…

Fix: after 26.0
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39335

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. Th…

Fix: after 7.1.1
Fix from $1,600 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39336

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields s…

Fix: 7.1.0+
Fix from $1,600 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39338

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search param…

Fix: after 7.0.5
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.9
CVE-2026-39328

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profil…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-39332

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-39333

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and Date…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.0
CVE-2026-35575

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s g…

Fix: 6.5.3+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-35576

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within th…

Fix: 7.0.0+
Fix from $1,950 2026-04-07
Quickdrop MEDIUM 6.1
CVE-2026-35608

QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application…

Fix: 1.5.3+
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-35574

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor al…

Fix: 6.5.3+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.6
CVE-2026-35534

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to inc…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Papra MEDIUM 5.4
CVE-2026-35460

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name dir…

Fix: 26.4.0+
Fix from $1,600 2026-04-07
Checkmk MEDIUM 5.4
CVE-2026-3466

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and …

Mitigation only
Fix from $1,600 2026-04-07
Mlflow MEDIUM 5.4
CVE-2026-33865

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authentic…

Fix: after 3.10.1
Fix from $1,600 2026-04-07
Bludit MEDIUM 5.4
CVE-2026-4420

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges…

Mitigation only
Fix from $1,600 2026-04-07
Ocs Inventory Server MEDIUM 6.1
CVE-2026-22675

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute…

Fix: after 2.12.3
Fix from $1,600 2026-04-06
Wegia MEDIUM 6.1
CVE-2026-35399

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through…

Fix: 3.6.9+
Fix from $1,600 2026-04-06
Lila MEDIUM 5.4
CVE-2026-35208

lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage…

Fix: 2026-03-31+
Fix from $1,600 2026-04-06
Webmail MEDIUM 5.4
CVE-2026-35390

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Poli…

Fix: 1.4.11+
Fix from $1,600 2026-04-06
Hugo MEDIUM 5.4
CVE-2026-35166

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escap…

Fix: 0.159.2+
Fix from $1,600 2026-04-06
Recipes MEDIUM 5.4
CVE-2026-35046

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authentic…

Fix: 2.6.4+
Fix from $1,600 2026-04-06
D Tale CRITICAL 9.8
CVE-2026-35052

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p…

Fix: 3.22.0+
Fix from $2,300 2026-04-06
Ci4ms CRITICAL 9.0
CVE-2026-34989

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-06
Ci4ms CRITICAL 9.0
CVE-2026-35035

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.2.0+
Fix from $2,300 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31313

An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbit…

No fix yet
Fix from $1,600 2026-04-06