Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-65560 Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65565 Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65544 Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65545 Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65509 Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65513 Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65515 Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-65517 Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-61963 Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-61964 Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-61982 Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-61961 Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-61959 Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-28177 Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-28178 Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.9 CVE-2026-28179 Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-28141 Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-28143 Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-28082 Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.4 CVE-2026-18501 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cr… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-8166 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-5158 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-5391 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' … No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2025-15028 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Si… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.4 CVE-2026-18400 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'd… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-18510 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.4 CVE-2026-16537 The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, al… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-18395 The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2025-15678 The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Autho… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2026-11588 The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisat… No fix yet Fix from $1,6002026-08-06