Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-66591 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows St… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.9 CVE-2026-27365 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored … Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66603 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allow… Fix unknown Fix from $4,0002026-08-18 HIGH 8.6 CVE-2026-52854 Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map p… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-52873 Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-rede… Fix unknown Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-54347 Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php ca… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-41921 Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows auth… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.7 CVE-2025-9211 Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers … Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-61696 Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitt… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-52609 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in sche… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-52606 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-30250 Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to … Fix unknown Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-55839 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link… Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-45115 MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to… Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-45116 MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field … Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73382 Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73393 Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73375 Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73378 Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73358 Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73359 Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-73360 Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73361 Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73362 Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73351 Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73190 Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73338 Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73342 Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-68565 Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. Fix unknown Fix from $4,0002026-08-18