Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
CRITICAL 9.6 CVE-2026-32626 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An… Anythingllm after 1.11.1 Fix from $2,3002026-03-16 CRITICAL 9.0 CVE-2026-32635 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n… Angular Cli 19.2.0 / 21.2.4+ Fix from $2,3002026-03-16 MEDIUM 5.4 CVE-2025-69241 Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbi… Raytha 1.4.6+ Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2025-69242 Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated … Raytha 1.4.6+ Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2025-69245 Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by… Raytha 1.4.6+ Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2025-69236 Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker with permissions to e… Raytha 1.4.6+ Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2025-69237 Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to … Raytha 1.4.6+ Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2017-20219 Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows attackers to execute arbitrary HTML a… No fix yet Fix from $1,6002026-03-16 HIGH 7.2 CVE-2016-20032 ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script… No fix yet Fix from $1,9502026-03-16 MEDIUM 6.1 CVE-2016-20036 Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed throu… Streaming Engine No fix yet Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2016-20027 ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script c… No fix yet Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2015-20116 Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename p… Realtyscript No fix yet Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2015-20118 Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations int… Realtyscript No fix yet Fix from $1,6002026-03-16 MEDIUM 5.4 CVE-2015-20119 Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious H… Realtyscript No fix yet Fix from $1,6002026-03-16 HIGH 7.5 CVE-2013-20006 Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly s… No fix yet Fix from $1,9502026-03-16 MEDIUM 6.1 CVE-2015-20114 Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code … Realtyscript No fix yet Fix from $1,6002026-03-16 MEDIUM 6.1 CVE-2015-20115 Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST p… Realtyscript No fix yet Fix from $1,6002026-03-16 MEDIUM 5.3 CVE-2013-20005 Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in us… No fix yet Fix from $1,6002026-03-16 MEDIUM 6.4 CVE-2026-3986 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and includi… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-32612 Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows a… Statamic 6.6.2+ Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32460 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ult… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.9 CVE-2026-32462 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32454 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-B… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32455 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonom… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32450 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommer… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32448 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32449 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Event Post themify-event-post… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32430 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Addons for Elemento… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32431 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edi… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32429 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-… Mitigation only Fix from $1,6002026-03-13