Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Checkmk MEDIUM 5.4
CVE-2026-33276

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to ex…

Mitigation only
Fix from $1,600 2026-03-31
Checkmk MEDIUM 5.4
CVE-2026-20915

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified HIGH 7.2
CVE-2026-4267

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['R…

Mitigation only
Fix from $1,950 2026-03-31
Unclassified MEDIUM 6.5
CVE-2026-34887

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stor…

Mitigation only
Fix from $1,600 2026-03-31
Anon Proxy Server MEDIUM 6.1
CVE-2025-41355

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in…

Mitigation only
Fix from $1,600 2026-03-31
Anon Proxy Server MEDIUM 6.1
CVE-2025-41356

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in t…

Mitigation only
Fix from $1,600 2026-03-31
Anon Proxy Server MEDIUM 6.1
CVE-2025-41357

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in t…

Mitigation only
Fix from $1,600 2026-03-31
Teampass MEDIUM 5.4
CVE-2026-3106

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' paramet…

Fix: 3.1.5.24+
Fix from $1,600 2026-03-31
Teampass MEDIUM 5.4
CVE-2026-3107

Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpo…

Fix: 3.1.5.24+
Fix from $1,600 2026-03-31
3dexperience MEDIUM 5.4
CVE-2025-10551

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE …

Mitigation only
Fix from $1,600 2026-03-31
3dexperience MEDIUM 5.4
CVE-2025-10553

A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE …

Mitigation only
Fix from $1,600 2026-03-31
Unclassified MEDIUM 6.1
CVE-2026-1877

The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to m…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified MEDIUM 6.1
CVE-2026-4146

The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-03-31
Basercms MEDIUM 6.1
CVE-2026-30879

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has …

Fix: 5.2.3+
Fix from $1,600 2026-03-31
Basercms MEDIUM 6.1
CVE-2026-32734

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been…

Fix: 5.2.3+
Fix from $1,600 2026-03-31
Ci4ms CRITICAL 9.0
CVE-2026-34557

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-03-30
Ci4ms CRITICAL 9.0
CVE-2026-34558

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-03-30
Ci4ms HIGH 7.2
CVE-2026-27599

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $1,950 2026-03-30
Tautulli CRITICAL 9.1
CVE-2026-32275

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP cal…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Smoothwall Express MEDIUM 6.1
CVE-2026-27508

Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improp…

Fix: after 3.0
Fix from $1,600 2026-03-30
Smoothwall Express MEDIUM 5.4
CVE-2026-26352

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to impr…

Fix: after 3.0
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30556

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the ind…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30557

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30558

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30559

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30560

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30561

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System CRITICAL 9.3
CVE-2026-30562

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $2,300 2026-03-30
Unclassified MEDIUM 6.1
CVE-2026-30082

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow a…

Mitigation only
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30563

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update…

No fix yet
Fix from $1,600 2026-03-30