Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-67196 Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaS… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.4 CVE-2026-14192 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc.… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.8 CVE-2026-16069 The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX action… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.8 CVE-2026-16293 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.4 CVE-2026-52520 Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authen… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-49131 OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privile… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-49132 OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScrip… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-66296 Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default H… Oaskit No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-38444 osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitizati… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-38446 A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-contro… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-69149 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,… Angular 20.3.27 / 21.2.19+ Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-69151 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,… Angular 20.3.27 / 21.2.19+ Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-18243 Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view prin… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-69092 Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messag… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-69075 FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-15383 The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauth… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-15931 The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval reque… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-13340 The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it regist… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.4 CVE-2026-12231 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-16063 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-15385 The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.1 CVE-2026-14841 The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-14864 The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.8 CVE-2026-14817 The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a… No fix yet Fix from $1,6002026-08-02 HIGH 7.6 CVE-2026-67352 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject… No fix yet Fix from $1,9502026-08-01 HIGH 7.2 CVE-2026-67333 better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the … No fix yet Fix from $1,9502026-08-01 HIGH 8.1 CVE-2026-67328 @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign … No fix yet Fix from $1,9502026-08-01 MEDIUM 5.1 CVE-2025-71404 better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where t… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.4 CVE-2026-18062 The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block I… No fix yet Fix from $1,6002026-08-01