Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-27225 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-… Experience Manager 6.5.24.0 / 2026.2.0+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-27226 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att… Experience Manager 6.5.24.0 / 2026.2.0+ Fix from $1,6002026-03-11 MEDIUM 6.4 CVE-2026-2569 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PDF page l… Mitigation only Fix from $1,6002026-03-11 MEDIUM 6.7 CVE-2026-31833 Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTM… Umbraco Cms 16.5.1 / 17.2.2+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-31822 Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by… Sylius 2.0.16 / 2.1.12+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-31807 SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous elements (<script>, <iframe>… Siyuan 3.5.10+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2026-31809 SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attributes for the javascript: pr… Siyuan 3.5.10+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-30948 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored c… Parse Server 8.6.17 / 9.5.2+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-2266 An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task lis… Enterprise Server 3.18.6 / 3.19.3+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-29177 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Cra… Craft Commerce 4.10.2 / 5.5.3+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-29175 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product T… Craft Commerce 5.5.3+ Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2025-70128 A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The applicati… Pluxml after 5.8.22 Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2025-36226 IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary … Aspera Faspex 5.0.15+ Fix from $1,6002026-03-10 MEDIUM 6.4 CVE-2026-3228 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in a… Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-30974 Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML … Copyparty 1.20.11+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-30934 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata f… Filebrowser after 1.2.9 Fix from $1,6002026-03-10 HIGH 7.2 CVE-2026-2724 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up t… Mitigation only Fix from $1,9502026-03-10 MEDIUM 6.1 CVE-2026-25972 An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 th… Fortisiem 7.3.5+ Fix from $1,6002026-03-10 CRITICAL 9.3 CVE-2026-26105 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20076+ Fix from $2,3002026-03-10 HIGH 7.2 CVE-2026-1261 The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 du… Mitigation only Fix from $1,9502026-03-10 MEDIUM 6.1 CVE-2025-70025 An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen generatedata 4.0.14. Generatedata Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2025-13902 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where aut… Modicon M258 Firmware 5.4.13.12+ Fix from $1,6002026-03-10 HIGH 8.8 CVE-2026-30917 Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table… Patch available Fix from $1,9502026-03-10 MEDIUM 6.1 CVE-2026-30918 facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives da… Facilemanager 6.0.4+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2026-30919 facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order X… Facilemanager 6.0.4+ Fix from $1,6002026-03-10 CRITICAL 9.0 CVE-2026-30862 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table … Appsmith 1.96+ Fix from $2,3002026-03-10 MEDIUM 6.1 CVE-2026-0489 Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated atta… Mitigation only Fix from $1,6002026-03-10 MEDIUM 6.1 CVE-2025-36173 Affected Product(s)Version(s)InfoSphere Data Architect9.2.1 Infosphere Data Architect No fix yet Fix from $1,6002026-03-10 CRITICAL 9.0 CVE-2026-25737 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili… Budibase after 3.24.0 Fix from $2,3002026-03-09 HIGH 8.8 CVE-2025-70038 An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allow… Twake Mitigation only Fix from $1,9502026-03-09