Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Workbench MEDIUM 6.1
CVE-2026-34951

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0…

Fix: 65.0.0+
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31352

An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitr…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31353

An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31354

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute ar…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31350

An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via in…

No fix yet
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.5
CVE-2026-34897

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows St…

Mitigation only
Fix from $1,600 2026-04-06
Web Interface MEDIUM 6.1
CVE-2026-33403

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5…

Fix: after 6.4.1
Fix from $1,600 2026-04-06
Web Interface MEDIUM 6.1
CVE-2026-33404

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5…

Fix: after 6.4.1
Fix from $1,600 2026-04-06
Web Interface MEDIUM 6.1
CVE-2026-33406

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5…

Fix: after 6.4.1
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.4
CVE-2026-31153

A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Mitigation only
Fix from $1,600 2026-04-06
Glpi MEDIUM 6.1
CVE-2026-26027

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the i…

Fix: 11.0.6+
Fix from $1,600 2026-04-06
Ask Expert Script CRITICAL 9.8
CVE-2019-25676

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code…

Mitigation only
Fix from $2,300 2026-04-05
Last User Threads MEDIUM 6.1
CVE-2018-25250

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scr…

Fix: after 1.2
Fix from $1,600 2026-04-04
Thankyou\/like System MEDIUM 6.1
CVE-2018-25247

MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread s…

Fix: after 3.0.0
Fix from $1,600 2026-04-04
Mybb Downloads HIGH 7.2
CVE-2018-25248

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through …

No fix yet
Fix from $1,950 2026-04-04
My Arcade MEDIUM 6.4
CVE-2018-25249

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts throug…

No fix yet
Fix from $1,600 2026-04-04
Unclassified HIGH 7.2
CVE-2026-2936

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all vers…

Mitigation only
Fix from $1,950 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-0626

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-2437

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified HIGH 7.2
CVE-2026-5425

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all version…

Mitigation only
Fix from $1,950 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-0737

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-0738

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-2600

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter i…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2025-15064

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Patch available
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-0552

The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all v…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-0664

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up t…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2025-13368

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Widget's 'onClick Even…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-2949

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.4
CVE-2026-2924

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoa…

Mitigation only
Fix from $1,600 2026-04-04
Emlog MEDIUM 6.1
CVE-2026-34229

Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment …

Fix: 2.6.8+
Fix from $1,600 2026-04-03