Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.2 CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged … No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stor… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.4 CVE-2026-70440 Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resultin… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-70441 Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cro… No fix yet Fix from $1,6002026-08-05 CRITICAL 9.3 CVE-2026-9195 A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.1 CVE-2026-53992 ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitra… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-17506 The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions … No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-71285 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted Jav… No fix yet Fix from $1,9502026-08-05 HIGH 8.5 CVE-2026-71274 OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HT… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.4 CVE-2026-71275 OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(reques… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.1 CVE-2026-71249 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) int… No fix yet Fix from $1,6002026-08-05 HIGH 8.7 CVE-2026-71236 Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri… No fix yet Fix from $1,9502026-08-05 HIGH 8.7 CVE-2026-71233 InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (r… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.4 CVE-2026-7441 The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive`… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.4 CVE-2026-6972 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.1 CVE-2026-17532 The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.1 CVE-2026-17505 The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versi… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-16942 The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to user… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-16573 The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to up… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.1 CVE-2026-16583 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded S… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.1 CVE-2026-8790 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in a… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-16143 The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field o… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.1 CVE-2026-51144 Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.1 CVE-2026-52370 A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in th… No fix yet Fix from $1,6002026-08-04 HIGH 8.7 CVE-2026-70492 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Mark… No fix yet Fix from $1,9502026-08-04 MEDIUM 5.0 CVE-2026-70588 Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize impor… No fix yet Fix from $1,6002026-08-04 HIGH 8.5 CVE-2026-65986 CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha… No fix yet Fix from $1,9502026-08-04 HIGH 8.2 CVE-2026-70486 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl ifr… No fix yet Fix from $1,9502026-08-04 MEDIUM 5.0 CVE-2026-66300 SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitr… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.1 CVE-2026-10032 The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent … No fix yet Fix from $1,6002026-08-04