Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2026-53667
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects fro…
React Router
7.18.0+
MEDIUM 6.9
CVE-2026-53668
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…
React Router
7.13.0+
CRITICAL 9.2
CVE-2026-66824
A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree dire…
Patch available
MEDIUM 6.9
CVE-2026-66825
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as u…
Patch available
MEDIUM 5.1
CVE-2026-59729
Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in rende…
Patch available
MEDIUM 5.4
CVE-2026-66031
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…
No fix yet
MEDIUM 5.4
CVE-2026-66029
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…
No fix yet
MEDIUM 5.4
CVE-2026-66030
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to injec…
No fix yet
HIGH 8.6
CVE-2026-59239
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user …
Patch available
MEDIUM 6.1
CVE-2026-66390
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicke…
Wicket
10.10.0+
CRITICAL 9.6
CVE-2026-66395
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to exe…
No fix yet
HIGH 8.4
CVE-2026-66396
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cr…
Mitigation only
HIGH 8.7
CVE-2026-66394
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to ex…
No fix yet
MEDIUM 6.5
CVE-2026-66434
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66445
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66448
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
No fix yet
MEDIUM 5.9
CVE-2026-66475
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions.
No fix yet
MEDIUM 6.5
CVE-2026-66433
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
No fix yet
MEDIUM 5.9
CVE-2026-65557
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65561
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65562
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
No fix yet
MEDIUM 5.9
CVE-2026-65563
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
No fix yet
MEDIUM 6.5
CVE-2026-59559
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
No fix yet
HIGH 7.1
CVE-2026-59553
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
No fix yet
HIGH 7.1
CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
No fix yet
HIGH 7.1
CVE-2026-59558
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
No fix yet
MEDIUM 6.3
CVE-2026-14856
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficien…
No fix yet
MEDIUM 5.1
CVE-2026-65764
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XS…
No fix yet
MEDIUM 6.8
CVE-2026-14827
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a p…
No fix yet
MEDIUM 6.1
CVE-2026-13400
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root caus…
No fix yet