Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Unclassified MEDIUM 6.4
CVE-2026-2501

The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-2496

The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 7.2
CVE-2026-2440

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissi…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.1
CVE-2026-2427

The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' parameters in all versions up to, …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.1
CVE-2026-2277

The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters in the search-pattern tester…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1899

The Any Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aps_slider shortcode in all versions up to, an…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1908

The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotform' shortcode in all versions …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1911

The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in the 'TwitterFeeds' shortcode i…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1914

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortcode in all versions up to, and…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1851

The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attribute in all versions up to, …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1854

The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1886

The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'go-night-pro-shortcode' sh…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1889

The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' shortcode in all versions up to…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1891

The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versio…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.1
CVE-2026-1647

The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up t…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1806

The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the t…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1822

The WP NG Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ng-weather' shortcode in all versions up to, an…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1397

The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget attributes in all versions up…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1575

The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shortcode in all versions up to, …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1275

The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' shortcode attribute in all ver…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-0609

The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-1093

The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of t…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.1
CVE-2025-13910

The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJAX endpoint in all versions up…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-4083

The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 7.2
CVE-2026-3368

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and i…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3516

The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.1
CVE-2026-3572

The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and inc…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-3350

The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-2430

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and in…

Patch available
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.4
CVE-2026-2352

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and inc…

Patch available
Fix from $1,600 2026-03-21