Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-53667 React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects fro… React Router 7.18.0+ Fix from $1,6002026-07-27 MEDIUM 6.9 CVE-2026-53668 React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable… React Router 7.13.0+ Fix from $1,6002026-07-27 CRITICAL 9.2 CVE-2026-66824 A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree dire… Patch available Fix from $2,3002026-07-27 MEDIUM 6.9 CVE-2026-66825 Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as u… Patch available Fix from $1,6002026-07-27 MEDIUM 5.1 CVE-2026-59729 Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in rende… Patch available Fix from $1,6002026-07-27 MEDIUM 5.4 CVE-2026-66031 Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.4 CVE-2026-66029 Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.4 CVE-2026-66030 Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to injec… No fix yet Fix from $1,6002026-07-27 HIGH 8.6 CVE-2026-59239 Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user … Patch available Fix from $1,9502026-07-27 MEDIUM 6.1 CVE-2026-66390 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke… Wicket 10.10.0+ Fix from $1,6002026-07-27 CRITICAL 9.6 CVE-2026-66395 SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to exe… No fix yet Fix from $2,3002026-07-27 HIGH 8.4 CVE-2026-66396 SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cr… Mitigation only Fix from $1,9502026-07-27 HIGH 8.7 CVE-2026-66394 SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to ex… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.5 CVE-2026-66434 Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-66445 Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-66448 Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 5.9 CVE-2026-66475 Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-66433 Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 5.9 CVE-2026-65557 Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-65561 Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-65562 Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 5.9 CVE-2026-65563 Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-59559 Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions. No fix yet Fix from $1,6002026-07-27 HIGH 7.1 CVE-2026-59553 Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.1 CVE-2026-59556 Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. No fix yet Fix from $1,9502026-07-27 HIGH 7.1 CVE-2026-59558 Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. No fix yet Fix from $1,9502026-07-27 MEDIUM 6.3 CVE-2026-14856 A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficien… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.1 CVE-2026-65764 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XS… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.8 CVE-2026-14827 The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a p… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-13400 Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root caus… No fix yet Fix from $1,6002026-07-27