Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified HIGH 7.1
CVE-2026-22520

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework a…

No fix yet
Fix from $1,950 2026-03-25
Unclassified HIGH 7.1
CVE-2026-22523

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin …

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.1
CVE-2026-22524

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows R…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.1
CVE-2026-22491

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.1
CVE-2025-69096

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This i…

Mitigation only
Fix from $1,950 2026-03-25
Tagify MEDIUM 5.4
CVE-2026-3212

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS)…

Fix: 1.2.49+
Fix from $1,600 2026-03-25
Islandora MEDIUM 5.4
CVE-2026-3215

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (X…

Fix: 2.17.5+
Fix from $1,600 2026-03-25
Saml Sso Service Provider MEDIUM 6.1
CVE-2026-3217

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross…

Fix: 3.1.3+
Fix from $1,600 2026-03-25
Quick Edit MEDIUM 5.4
CVE-2026-2348

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (…

Fix: 1.0.5+
Fix from $1,600 2026-03-25
Ui Icons MEDIUM 6.1
CVE-2026-2349

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XS…

Fix: 1.0.1+
Fix from $1,600 2026-03-25
Kiteworks MEDIUM 5.4
CVE-2026-24750

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper…

Fix: 9.2.1+
Fix from $1,600 2026-03-25
Catalyst Sd Wan Manager MEDIUM 5.4
CVE-2026-20108

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cro…

Fix: 20.12.5.3 / 20.15.4.2+
Fix from $1,600 2026-03-25
Support Board MEDIUM 5.4
CVE-2026-4816

A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScr…

Fix: 3.7.8+
Fix from $1,600 2026-03-25
Indoor Connect 8855 Firmware MEDIUM 6.1
CVE-2025-40842

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthori…

Fix: 2025.q3+
Fix from $1,600 2026-03-25
Infrastructure Analytics Advisor MEDIUM 6.1
CVE-2026-2072

Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue af…

Fix: 11.0.5-00+
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.4
CVE-2026-4766

The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up…

Mitigation only
Fix from $1,600 2026-03-25
Commonmark MEDIUM 6.1
CVE-2026-33347

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerab…

Fix: 2.8.2+
Fix from $1,600 2026-03-24
Orpc MEDIUM 5.4
CVE-2026-33331

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scr…

Fix: 1.13.9+
Fix from $1,600 2026-03-24
Wallos MEDIUM 5.4
CVE-2026-33400

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in t…

Fix: 4.7.0+
Fix from $1,600 2026-03-24
Vikunja CRITICAL 9.6
CVE-2026-33334

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…

Fix: 2.2.2+
Fix from $2,300 2026-03-24
Jizhicms MEDIUM 5.4
CVE-2026-29840

JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. T…

Fix: after 2.5.6
Fix from $1,600 2026-03-24
Icms MEDIUM 6.1
CVE-2026-30661

iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allow…

No fix yet
Fix from $1,600 2026-03-24
Android Imagemagick7 MEDIUM 6.1
CVE-2026-4754

CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

Fix: 7.1.2-11+
Fix from $1,600 2026-03-24
Online Lawyer Management System MEDIUM 5.4
CVE-2026-4626

A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m…

No fix yet
Fix from $1,600 2026-03-24
Rails MEDIUM 6.1
CVE-2026-33170

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-24
Rails MEDIUM 6.1
CVE-2026-33167

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions p…

Fix: 8.1.2.1+
Fix from $1,600 2026-03-23
Connect Cms HIGH 8.7
CVE-2026-32277

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue…

Fix: 1.41.1 / 2.41.1+
Fix from $1,950 2026-03-23
Csweb MEDIUM 5.4
CVE-2025-60948

Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that…

Patch available
Fix from $1,600 2026-03-23
Mailenable MEDIUM 6.1
CVE-2026-32851

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex…

Fix: 10.55+
Fix from $1,600 2026-03-23
Mailenable MEDIUM 6.1
CVE-2026-32852

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex…

Fix: 10.55+
Fix from $1,600 2026-03-23