Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-32424 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows S… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.9 CVE-2026-32419 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano List category posts list-catego… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32411 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calendly embed-calendly-scheduling… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32403 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion … Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32359 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.9 CVE-2026-32360 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews wi… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32361 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-cal… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.9 CVE-2026-32351 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32352 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor a… Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-32356 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-B… Mitigation only Fix from $1,6002026-03-13 HIGH 7.6 CVE-2026-32308 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with se… Oneuptime 10.0.23+ Fix from $1,9502026-03-13 MEDIUM 6.5 CVE-2026-31918 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immonex Kickstart immonex-kickstart all… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.5 CVE-2026-22209 wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 MEDIUM 6.1 CVE-2026-22210 wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-22183 wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated use… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-0835 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2025-14504 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2025-13702 IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability… Sterling Partner Engagement Manager 6.2.3.6 / 6.2.4.3+ Fix from $1,6002026-03-13 MEDIUM 6.1 CVE-2025-12453 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vu… Vertica 25.4.0-0+ Fix from $1,6002026-03-13 MEDIUM 6.1 CVE-2025-12454 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vu… Vertica 25.2.0+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2023-40693 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vul… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-32139 Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads… Dataease 2.10.20+ Fix from $1,6002026-03-12 MEDIUM 6.1 CVE-2026-31860 Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event h… Unhead 2.1.11+ Fix from $1,6002026-03-12 MEDIUM 6.1 CVE-2026-31873 Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-s… Unhead 2.1.11+ Fix from $1,6002026-03-12 HIGH 8.1 CVE-2026-25529 Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included i… Postal 3.3.5+ Fix from $1,9502026-03-12 HIGH 8.6 CVE-2026-2513 A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by … Mitigation only Fix from $1,9502026-03-12 HIGH 8.6 CVE-2026-2514 In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may … Mitigation only Fix from $1,9502026-03-12 MEDIUM 6.1 CVE-2026-2987 The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 202602… Mitigation only Fix from $1,6002026-03-12 MEDIUM 5.4 CVE-2026-32117 The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supp… Grafanacubism Panel after 0.1.2 Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-32124 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJ… Openemr 8.0.0.1+ Fix from $1,6002026-03-11