Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Security Verify Access MEDIUM 5.4
CVE-2026-4364

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $1,600 2026-04-01
Filebrowser CRITICAL 9.0
CVE-2026-34529

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…

Fix: 2.62.2+
Fix from $2,300 2026-04-01
Filebrowser MEDIUM 6.9
CVE-2026-34530

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…

Fix: 2.62.2+
Fix from $1,600 2026-04-01
Payload HIGH 8.7
CVE-2026-34748

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS…

Fix: 3.78.0+
Fix from $1,950 2026-04-01
Notesnook Mobile MEDIUM 6.1
CVE-2026-33978

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share …

Fix: 3.3.17+
Fix from $1,600 2026-04-01
Unclassified MEDIUM 6.1
CVE-2026-20085

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack …

Mitigation only
Fix from $1,600 2026-04-01
Zoo Management System MEDIUM 6.1
CVE-2026-30526

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login p…

No fix yet
Fix from $1,600 2026-04-01
Unclassified MEDIUM 5.4
CVE-2026-29598

Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers …

Mitigation only
Fix from $1,600 2026-04-01
Unclassified MEDIUM 6.4
CVE-2025-13535

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in al…

Mitigation only
Fix from $1,600 2026-04-01
Fm MEDIUM 6.1
CVE-2026-3877

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a ma…

Fix: 10.13.403+
Fix from $1,600 2026-04-01
Joomla\! MEDIUM 5.4
CVE-2026-21631

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Fix: 5.4.4 / 6.0.4+
Fix from $1,600 2026-04-01
Joomla\! MEDIUM 5.4
CVE-2026-21632

Lack of output escaping for article titles leads to XSS vectors in various locations.

Fix: 5.4.4 / 6.0.4+
Fix from $1,600 2026-04-01
Unclassified MEDIUM 6.5
CVE-2026-34889

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery P…

Mitigation only
Fix from $1,600 2026-04-01
Simple Laundry System MEDIUM 6.1
CVE-2026-5255

A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component …

No fix yet
Fix from $1,600 2026-04-01
Xenforo MEDIUM 5.4
CVE-2026-35054

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts throug…

Fix: 2.3.9+
Fix from $1,600 2026-04-01
Xenforo MEDIUM 6.1
CVE-2026-35055

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicio…

Fix: 2.2.18 / 2.3.9+
Fix from $1,600 2026-04-01
Xenforo MEDIUM 5.4
CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy pr…

Fix: 2.2.19 / 2.3.10+
Fix from $1,600 2026-04-01
Unclassified MEDIUM 6.4
CVE-2026-2480

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the…

Mitigation only
Fix from $1,600 2026-03-31
Siyuan HIGH 8.2
CVE-2026-34585

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side…

Fix: 3.6.2+
Fix from $1,950 2026-03-31
Siyuan MEDIUM 6.1
CVE-2026-34605

SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to…

Fix: 3.6.2+
Fix from $1,600 2026-03-31
Siyuan CRITICAL 9.0
CVE-2026-34448

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field …

Fix: 3.6.2+
Fix from $2,300 2026-03-31
Og Image MEDIUM 6.1
CVE-2026-34405

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…

Fix: 6.2.5+
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.1
CVE-2026-34739

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request paramete…

Fix: after 26.0
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.4
CVE-2026-34716

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifica…

Fix: after 26.0
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.1
CVE-2026-34396

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms wi…

Fix: after 26.0
Fix from $1,600 2026-03-31
Captcha Protect MEDIUM 6.1
CVE-2026-34206

Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet.…

Fix: 1.12.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 5.4
CVE-2026-32607

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 5.4
CVE-2026-32243

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 5.4
CVE-2026-32273

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Slippers MEDIUM 6.1
CVE-2026-34231

Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} templat…

Fix: after 0.6.2
Fix from $1,600 2026-03-31