Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-13726 The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated a… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.1 CVE-2026-14190 The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticate… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-10082 The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users … No fix yet Fix from $1,6002026-07-27 MEDIUM 6.1 CVE-2026-12982 The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an u… No fix yet Fix from $1,6002026-07-27 HIGH 8.2 CVE-2026-15928 XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. No fix yet Fix from $1,9502026-07-27 HIGH 8.1 CVE-2026-17496 NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInne… Patch available Fix from $1,9502026-07-26 MEDIUM 6.4 CVE-2026-15425 The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug … No fix yet Fix from $1,6002026-07-25 MEDIUM 5.4 CVE-2026-57531 Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers … Patch available Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-57530 Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that… Patch available Fix from $1,6002026-07-24 MEDIUM 6.1 CVE-2026-8308 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W… No fix yet Fix from $1,6002026-07-24 HIGH 8.7 CVE-2026-55730 Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to exec… No fix yet Fix from $1,9502026-07-24 HIGH 8.7 CVE-2026-12496 Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD t… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.1 CVE-2026-66010 DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing at… Dompurify 3.4.12+ Fix from $1,6002026-07-24 HIGH 8.7 CVE-2026-15810 A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28,… No fix yet Fix from $1,9502026-07-24 HIGH 7.2 CVE-2026-15401 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions … No fix yet Fix from $1,9502026-07-24 MEDIUM 6.4 CVE-2026-15739 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all ve… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15821 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in al… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.1 CVE-2026-15346 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15464 The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15648 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, a… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15653 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backen… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15665 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Sh… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15755 The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versio… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15333 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15334 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-6454 The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15100 The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all … No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2025-9205 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-15968 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects M… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $1,6002026-07-23 MEDIUM 5.1 CVE-2026-65763 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vul… No fix yet Fix from $1,6002026-07-23