Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Sales And Inventory System MEDIUM 6.1
CVE-2026-30564

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30565

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…

No fix yet
Fix from $1,600 2026-03-30
Sales And Inventory System MEDIUM 6.1
CVE-2026-30566

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…

No fix yet
Fix from $1,600 2026-03-30
Unclassified MEDIUM 6.4
CVE-2026-2602

The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-03-29
Unclassified MEDIUM 5.4
CVE-2026-2595

The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1…

Mitigation only
Fix from $1,600 2026-03-28
Notesnook Desktop HIGH 8.6
CVE-2026-33955

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi…

Fix: 3.3.11+
Fix from $1,950 2026-03-27
Notesnook Desktop CRITICAL 9.6
CVE-2026-33976

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can …

Fix: 3.3.11 / 3.3.17+
Fix from $2,300 2026-03-27
Express Xss Sanitizer HIGH 8.2
CVE-2026-33979

Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to preve…

Fix: 2.0.2+
Fix from $1,950 2026-03-27
Handlebars HIGH 8.2
CVE-2026-33941

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Statamic MEDIUM 6.1
CVE-2026-33883

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could …

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Home Assistant MEDIUM 5.4
CVE-2026-33045

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…

Fix: 2026.1.0+
Fix from $1,600 2026-03-27
Home Assistant MEDIUM 5.4
CVE-2026-33044

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…

Fix: 2026.1.0+
Fix from $1,600 2026-03-27
Avideo HIGH 8.2
CVE-2026-34375

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes th…

Fix: after 26.0
Fix from $1,950 2026-03-27
Inventory System MEDIUM 6.1
CVE-2026-30567

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "li…

No fix yet
Fix from $1,600 2026-03-27
Inventory System MEDIUM 6.1
CVE-2026-30569

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the vie…

No fix yet
Fix from $1,600 2026-03-27
Inventory System MEDIUM 6.1
CVE-2026-30570

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limi…

No fix yet
Fix from $1,600 2026-03-27
Inventory System MEDIUM 6.1
CVE-2026-30571

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "l…

No fix yet
Fix from $1,600 2026-03-27
Online Food Ordering System MEDIUM 5.4
CVE-2026-30527

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within …

No fix yet
Fix from $1,600 2026-03-27
Unclassified MEDIUM 5.1
CVE-2026-5010

A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript cod…

Mitigation only
Fix from $1,600 2026-03-27
Langflow MEDIUM 5.4
CVE-2026-5026

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. S…

Mitigation only
Fix from $1,600 2026-03-27
Openbao MEDIUM 6.1
CVE-2026-33758

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio…

Fix: 2.5.2+
Fix from $1,600 2026-03-27
Dspace MEDIUM 6.1
CVE-2025-61190

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The …

No fix yet
Fix from $1,600 2026-03-27
Unclassified MEDIUM 5.4
CVE-2026-32859

ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to…

Patch available
Fix from $1,600 2026-03-27
Bludit MEDIUM 5.4
CVE-2026-25100

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges…

Fix: 3.18.2+
Fix from $1,600 2026-03-27
Unclassified HIGH 7.0
CVE-2026-3457

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows a…

Mitigation only
Fix from $1,950 2026-03-27
Unclassified MEDIUM 5.4
CVE-2026-33559

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin …

Mitigation only
Fix from $1,600 2026-03-27
Prestashop MEDIUM 5.4
CVE-2026-33673

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS)…

Fix: 8.2.5 / 9.1.0+
Fix from $1,600 2026-03-26
Uploady MEDIUM 5.4
CVE-2026-33653

Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2…

Fix: 3.1.2+
Fix from $1,600 2026-03-26
Kestra MEDIUM 5.4
CVE-2026-33664

Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — des…

Fix: after 1.3.3
Fix from $1,600 2026-03-26
Google Analytics Ga4 MEDIUM 6.1
CVE-2026-3529

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site S…

Fix: 1.1.14+
Fix from $1,600 2026-03-26