Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Budibase HIGH 8.7
CVE-2026-35218

Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, querie…

Fix: 3.32.5+
Fix from $1,950 2026-04-03
Casdoor MEDIUM 5.4
CVE-2026-5468

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument …

Mitigation only
Fix from $1,600 2026-04-03
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2026-4107

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

Fix: 5.8+
Fix from $1,600 2026-04-03
Webmail MEDIUM 6.1
CVE-2026-35539

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mod…

Fix: 1.5.14 / 1.6.14+
Fix from $1,600 2026-04-03
Shynet MEDIUM 6.1
CVE-2026-35508

Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,

Fix: 0.14.0+
Fix from $1,600 2026-04-03
Zenshare Suite MEDIUM 6.1
CVE-2026-30251

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attack…

Mitigation only
Fix from $1,600 2026-04-02
Zencrm MEDIUM 6.1
CVE-2026-30252

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows atta…

Mitigation only
Fix from $1,600 2026-04-02
Cveclient MEDIUM 6.1
CVE-2026-35466

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Fix: 1.0.24+
Fix from $1,600 2026-04-02
Hoppscotch MEDIUM 5.4
CVE-2026-34848

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow to…

Fix: 2026.3.0+
Fix from $1,600 2026-04-02
Hoppscotch CRITICAL 9.3
CVE-2026-34932

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Unclassified HIGH 7.8
CVE-2026-5429

Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat acto…

Mitigation only
Fix from $1,950 2026-04-02
Unclassified HIGH 8.2
CVE-2026-34725

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c…

Patch available
Fix from $1,950 2026-04-02
Learning MEDIUM 6.1
CVE-2026-34606

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, …

Fix: 2.48.0+
Fix from $1,600 2026-04-02
Yeswiki MEDIUM 6.1
CVE-2026-34598

YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious att…

Fix: 4.6.0+
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34821

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An auth…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34822

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authe…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34823

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Phpmyfaq MEDIUM 5.4
CVE-2026-34974

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed …

Fix: 4.1.1+
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34816

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An auth…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34817

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authen…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34818

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authen…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34819

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authentic…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34820

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacke…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34812

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenti…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34813

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated a…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34814

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34815

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticat…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34807

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated …

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34808

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticate…

Fix: after 3.3.25
Fix from $1,600 2026-04-02
Firewall Community MEDIUM 5.4
CVE-2026-34809

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated at…

Fix: after 3.3.25
Fix from $1,600 2026-04-02