Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.1
CVE-2026-15032

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing una…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-15245

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into a…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-15386

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.1
CVE-2026-14331

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, le…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.4
CVE-2026-12801

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-sep…

No fix yet
Fix from $1,600 2026-08-07
Sharepoint Online CRITICAL 9.6
CVE-2026-70332

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.2
CVE-2026-71445

AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag o…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.9
CVE-2026-71446

AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScrip…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.9
CVE-2026-71447

AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affect…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.1
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsa…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.1
CVE-2026-71435

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-49391

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-48081

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN ca…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-47185

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authent…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.8
CVE-2024-39024

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66711

Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66702

Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-66703

Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66705

Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-66706

Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66707

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-66688

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66690

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66694

Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66664

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66440

Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66457

Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66663

Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-66439

Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.

No fix yet
Fix from $1,950 2026-08-06