Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-32125 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the … Openemr 8.0.0.1+ Fix from $1,6002026-03-11 CRITICAL 9.0 CVE-2026-32118 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scriptin… Openemr 8.0.0.1+ Fix from $2,3002026-03-11 MEDIUM 5.4 CVE-2026-32121 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescriptio… Openemr 8.0.0.1+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-32095 Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers trea… Plunk 0.7.1+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-31876 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in No… Notesnook Desktop 3.3.9 / 3.3.15+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-31879 Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission check… Frappe 14.100.2 / 15.101.0+ Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-31868 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacke… Parse Server 8.6.30 / 9.6.0+ Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-31859 Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize… Craft Cms 4.17.3 / 5.9.7+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-30235 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenPr… Openproject 17.2.0+ Fix from $1,6002026-03-11 MEDIUM 6.3 CVE-2026-20162 In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510.4, 10.1.2507.15, 10.0.2503.1… Splunk 9.3.9 / 9.3.2411.123+ Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-20116 A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified … Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-20117 A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote at… Unified Contact Center Express after 15.0 Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-1090 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could … GitLab 18.7.6 / 18.8.6+ Fix from $1,6002026-03-11 HIGH 7.2 CVE-2026-3178 The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, a… Mitigation only Fix from $1,9502026-03-11 MEDIUM 6.4 CVE-2026-3492 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a … Mitigation only Fix from $1,6002026-03-11 HIGH 7.2 CVE-2026-3231 The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and c… Mitigation only Fix from $1,9502026-03-11 HIGH 7.2 CVE-2026-1454 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,… Mitigation only Fix from $1,9502026-03-11 MEDIUM 6.1 CVE-2026-3825 IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaSc… Organization Portal System Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.4 CVE-2026-3534 The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post … Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-3884 Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than… Spin.js 3.0.0+ Fix from $1,6002026-03-11 MEDIUM 6.4 CVE-2026-2358 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all … Patch available Fix from $1,6002026-03-11 HIGH 7.1 CVE-2026-2466 The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected C… Mitigation only Fix from $1,9502026-03-11 MEDIUM 6.4 CVE-2026-2707 The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and i… Patch available Fix from $1,6002026-03-11 HIGH 8.1 CVE-2026-21361 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 HIGH 8.0 CVE-2026-21311 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 MEDIUM 5.4 CVE-2026-21292 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (… Commerce B2b 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 HIGH 8.1 CVE-2026-21284 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (… Commerce B2b 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 HIGH 8.7 CVE-2026-21290 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (… Commerce B2b 1.3.3 / 2.4.4+ Fix from $1,9502026-03-11 MEDIUM 6.1 CVE-2025-12473 The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all versions up to, and including… Mitigation only Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-27262 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att… Experience Manager 6.5.24.0 / 2026.2.0+ Fix from $1,6002026-03-11