Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Suitecrm MEDIUM 6.1
CVE-2026-29100

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML i…

Fix: 7.15.1+
Fix from $1,600 2026-03-19
Siyuan CRITICAL 9.0
CVE-2026-32751

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via inner…

Fix: 3.6.1+
Fix from $2,300 2026-03-19
Freescout CRITICAL 9.3
CVE-2026-32754

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scr…

Fix: 1.8.209+
Fix from $2,300 2026-03-19
Openclaw MEDIUM 6.1
CVE-2026-32040

OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary …

Fix: 2026.2.23+
Fix from $1,600 2026-03-19
Openemr HIGH 8.7
CVE-2026-33346

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site script…

Fix: 8.0.0.2+
Fix from $1,950 2026-03-19
Openemr MEDIUM 5.4
CVE-2026-33299

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Openemr MEDIUM 5.4
CVE-2026-33303

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to …

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Discourse MEDIUM 6.1
CVE-2026-27570

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConver…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Discourse MEDIUM 6.1
CVE-2026-27740

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerabilit…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32869

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case informat…

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32866

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated …

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32868

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An a…

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Unclassified MEDIUM 5.1
CVE-2026-32843

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.ph…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.1
CVE-2026-27068

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt a…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.1
CVE-2026-27070

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.T…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.1
CVE-2026-25438

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks all…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.1
CVE-2026-25442

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified MEDIUM 6.5
CVE-2025-62043

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue …

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.1
CVE-2025-67618

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.T…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.1
CVE-2025-68836

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows R…

Mitigation only
Fix from $1,950 2026-03-19
Connections MEDIUM 5.4
CVE-2026-21788

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.1
CVE-2025-50001

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Refle…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.1
CVE-2025-53222

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription al…

Mitigation only
Fix from $1,950 2026-03-19
Unica MEDIUM 5.4
CVE-2024-42210

A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known …

Fix: 12.1.9+
Fix from $1,600 2026-03-19
Unclassified MEDIUM 6.4
CVE-2026-4120

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter with…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified MEDIUM 6.4
CVE-2026-4006

The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versio…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified MEDIUM 5.9
CVE-2026-28044

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue…

Mitigation only
Fix from $1,600 2026-03-19
Unclassified HIGH 7.1
CVE-2026-28073

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected …

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.2
CVE-2026-1238

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, …

Mitigation only
Fix from $1,950 2026-03-19
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2025-15051

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2026-03-19