Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Mantisbt MEDIUM 6.1
CVE-2026-33517

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name…

Patch available
Fix from $1,600 2026-03-23
Mantisbt MEDIUM 6.1
CVE-2026-33548

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (…

Patch available
Fix from $1,600 2026-03-23
Online Lawyer Management System MEDIUM 5.4
CVE-2026-4596

A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. Th…

No fix yet
Fix from $1,600 2026-03-23
Mailenable MEDIUM 6.1
CVE-2026-32850

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex…

Fix: 10.55+
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.1
CVE-2025-52204

A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter

Mitigation only
Fix from $1,600 2026-03-23
Tiki MEDIUM 5.4
CVE-2024-46878

A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability all…

Fix: 27.1+
Fix from $1,600 2026-03-23
Tiki MEDIUM 5.4
CVE-2024-46879

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vuln…

Fix: 21.11+
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.4
CVE-2026-33683

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "abou…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 6.1
CVE-2026-33499

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.4
CVE-2026-33500

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a cus…

Fix: after 26.0
Fix from $1,600 2026-03-23
Vehicle Record Management System MEDIUM 6.1
CVE-2024-51226

A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allo…

No fix yet
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.4
CVE-2025-6229

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & El…

Mitigation only
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.4
CVE-2026-33295

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plug…

Fix: 26.0+
Fix from $1,600 2026-03-22
Unclassified MEDIUM 6.4
CVE-2026-3427

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `j…

Patch available
Fix from $1,600 2026-03-22
Sogo MEDIUM 6.1
CVE-2025-71276

SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

Fix: 5.12.5+
Fix from $1,600 2026-03-22
Unclassified MEDIUM 6.4
CVE-2026-4086

The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4067

The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.1
CVE-2026-4069

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4072

The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4077

The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4084

The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shor…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4022

The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_type' shortcode …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3997

The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] short…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3996

The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3617

The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' shortcode attributes in all versio…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3619

The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute in the [sheets2table-render-t…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3554

The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in all vers…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.5
CVE-2026-3347

The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[message]` parameter in all vers…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3333

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 7.2
CVE-2026-3003

The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, an…

Mitigation only
Fix from $1,950 2026-03-21