Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Discourse MEDIUM 5.4
CVE-2026-33411

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a potential stored XSS in topic tit…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-20
Nltk MEDIUM 6.1
CVE-2026-33230

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…

Fix: after 3.9.3
Fix from $1,600 2026-03-20
Avo MEDIUM 6.1
CVE-2026-33209

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exist…

Fix: 3.30.3+
Fix from $1,600 2026-03-20
Statamic HIGH 8.7
CVE-2026-33172

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…

Fix: 5.73.14 / 6.7.0+
Fix from $1,950 2026-03-20
Pyspector MEDIUM 6.1
CVE-2026-33140

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and pri…

Fix: 0.1.7+
Fix from $1,600 2026-03-20
Syncfusion MEDIUM 5.4
CVE-2025-63260

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

No fix yet
Fix from $1,600 2026-03-20
Php Api Doc MEDIUM 6.1
CVE-2026-32844

XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attack…

Fix: after 2019-03-24
Fix from $1,600 2026-03-20
File Thingie MEDIUM 6.5
CVE-2026-30578

File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbit…

Mitigation only
Fix from $1,600 2026-03-20
File Thingie MEDIUM 6.5
CVE-2026-30579

File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a…

Mitigation only
Fix from $1,600 2026-03-20
Dootask MEDIUM 6.1
CVE-2026-29828

DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc.

Fix: after 1.6.27
Fix from $1,600 2026-03-20
Textpattern MEDIUM 6.1
CVE-2026-32986

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploit…

No fix yet
Fix from $1,600 2026-03-20
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2026-33370

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase…

Fix: 10.1.16+
Fix from $1,600 2026-03-20
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2026-33368

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/…

Fix: 10.1.16+
Fix from $1,600 2026-03-20
Assist MEDIUM 6.1
CVE-2026-31382

The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.

No fix yet
Fix from $1,600 2026-03-20
Wegia MEDIUM 6.1
CVE-2026-33135

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_me…

Fix: 3.6.7+
Fix from $1,600 2026-03-20
Wegia MEDIUM 6.1
CVE-2026-33136

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_…

Fix: 3.6.7+
Fix from $1,600 2026-03-20
Unclassified MEDIUM 5.9
CVE-2024-31119

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyllou Special Box for Content a…

Mitigation only
Fix from $1,600 2026-03-20
Filament MEDIUM 5.4
CVE-2026-33080

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two …

Fix: 4.8.5 / 5.3.5+
Fix from $1,600 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33066

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33067

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Jexactyl MEDIUM 5.4
CVE-2026-33061

Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80ef…

Fix: after 3.8.0
Fix from $1,600 2026-03-20
University Management System MEDIUM 6.1
CVE-2026-4474

A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.…

No fix yet
Fix from $1,600 2026-03-20
Craft Cms MEDIUM 5.4
CVE-2026-33051

Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor render…

Fix: 5.9.11+
Fix from $1,600 2026-03-20
Avideo MEDIUM 6.1
CVE-2026-33035

WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attacker…

Fix: 26.0+
Fix from $1,600 2026-03-20
Siyuan MEDIUM 6.1
CVE-2026-32940

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and…

Fix: 3.6.1+
Fix from $1,600 2026-03-20
Anchorr CRITICAL 9.6
CVE-2026-32890

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…

Fix: after 1.4.1
Fix from $2,300 2026-03-20
Churchcrm MEDIUM 6.4
CVE-2026-32880

ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaSc…

Fix: 7.0.2+
Fix from $1,600 2026-03-20
Admidio MEDIUM 5.4
CVE-2026-32757

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value inst…

Fix: 5.0.7+
Fix from $1,600 2026-03-20
Discourse MEDIUM 5.4
CVE-2026-33395

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discourse-graphviz plugin contains …

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Suitecrm MEDIUM 6.1
CVE-2026-29106

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the val…

Fix: 7.15.1 / 8.9.3+
Fix from $1,600 2026-03-19