Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Lychee MEDIUM 5.4
CVE-2026-33738

Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and re…

Fix: 7.5.3+
Fix from $1,600 2026-03-26
Invoice Ninja MEDIUM 5.4
CVE-2026-33742

Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 a…

Fix: 5.13.4+
Fix from $1,600 2026-03-26
Calculation Fields MEDIUM 6.1
CVE-2026-3528

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scr…

Fix: 1.0.4+
Fix from $1,600 2026-03-26
Invoice Ninja MEDIUM 5.4
CVE-2026-33628

Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja…

Fix: 5.13.4+
Fix from $1,600 2026-03-26
Authelia MEDIUM 6.1
CVE-2026-33525

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via …

No fix yet
Fix from $1,600 2026-03-26
Staffwiki MEDIUM 6.1
CVE-2026-29969

A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Jav…

No fix yet
Fix from $1,600 2026-03-26
Stirling Pdf MEDIUM 6.1
CVE-2026-34071

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version 2.7.3, the /api/v1/convert/em…

No fix yet
Fix from $1,600 2026-03-26
Sakai MEDIUM 6.1
CVE-2026-33402

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contai…

Fix: 23.5 / 25.2+
Fix from $1,600 2026-03-26
Lightcms MEDIUM 6.1
CVE-2026-29934

A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript …

No fix yet
Fix from $1,600 2026-03-26
Timo MEDIUM 6.1
CVE-2026-30162

Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.

No fix yet
Fix from $1,600 2026-03-26
Yzmcms MEDIUM 6.1
CVE-2026-29933

A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascri…

No fix yet
Fix from $1,600 2026-03-26
Observability Self Hosted HIGH 8.7
CVE-2026-28297

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…

Fix: 2026.1.1+
Fix from $1,950 2026-03-26
Observability Self Hosted HIGH 8.1
CVE-2026-28298

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…

Fix: 2026.1.1+
Fix from $1,950 2026-03-26
Unclassified HIGH 7.2
CVE-2026-2231

The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.…

Mitigation only
Fix from $1,950 2026-03-26
Gdtaller MEDIUM 6.1
CVE-2025-41027

Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br…

Mitigation only
Fix from $1,600 2026-03-26
Gdtaller MEDIUM 6.1
CVE-2025-41026

Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br…

Mitigation only
Fix from $1,600 2026-03-26
E Ticaret MEDIUM 6.1
CVE-2018-25210

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to m…

Fix: after 4.0.0
Fix from $1,600 2026-03-26
Simple Laundry System MEDIUM 6.1
CVE-2026-4849

A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component …

No fix yet
Fix from $1,600 2026-03-26
Unclassified HIGH 7.2
CVE-2026-4329

The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified MEDIUM 6.4
CVE-2026-4389

The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` …

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.4
CVE-2026-4278

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.4
CVE-2026-4075

The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up t…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 5.4
CVE-2026-4335

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to,…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.1
CVE-2026-1986

The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t…

Mitigation only
Fix from $1,600 2026-03-26
Openemr MEDIUM 6.1
CVE-2026-33933

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to ver…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
Openemr MEDIUM 5.4
CVE-2026-33932

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-sit…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-26
Openemr MEDIUM 5.4
CVE-2026-33911

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-25
Openemr MEDIUM 5.4
CVE-2026-33912

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated a…

Fix: 8.0.0.3+
Fix from $1,600 2026-03-25
Openemr MEDIUM 5.4
CVE-2026-33348

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role …

Fix: 8.0.0.3+
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 5.4
CVE-2026-2483

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25