Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2026-13726
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated a…
No fix yet
MEDIUM 6.1
CVE-2026-14190
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticate…
No fix yet
MEDIUM 6.1
CVE-2026-10082
The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users …
No fix yet
MEDIUM 6.1
CVE-2026-12982
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an u…
No fix yet
HIGH 8.2
CVE-2026-15928
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
No fix yet
HIGH 8.1
CVE-2026-17496
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInne…
Patch available
MEDIUM 6.4
CVE-2026-15425
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug …
No fix yet
MEDIUM 5.4
CVE-2026-57531
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers …
Patch available
MEDIUM 5.4
CVE-2026-57530
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that…
Patch available
MEDIUM 6.1
CVE-2026-8308
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W…
No fix yet
HIGH 8.7
CVE-2026-55730
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to exec…
No fix yet
HIGH 8.7
CVE-2026-12496
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD t…
No fix yet
MEDIUM 6.1
CVE-2026-66010
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing at…
Dompurify
3.4.12+
HIGH 8.7
CVE-2026-15810
A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28,…
No fix yet
HIGH 7.2
CVE-2026-15401
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions …
No fix yet
MEDIUM 6.4
CVE-2026-15739
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all ve…
No fix yet
MEDIUM 6.4
CVE-2026-15821
The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in al…
No fix yet
MEDIUM 6.1
CVE-2026-15346
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all…
No fix yet
MEDIUM 6.4
CVE-2026-15464
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,…
No fix yet
MEDIUM 6.4
CVE-2026-15648
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, a…
No fix yet
MEDIUM 6.4
CVE-2026-15653
The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backen…
No fix yet
MEDIUM 6.4
CVE-2026-15665
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Sh…
No fix yet
MEDIUM 6.4
CVE-2026-15755
The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versio…
No fix yet
MEDIUM 6.4
CVE-2026-15333
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…
No fix yet
MEDIUM 6.4
CVE-2026-15334
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…
No fix yet
MEDIUM 6.4
CVE-2026-6454
The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i…
No fix yet
MEDIUM 6.4
CVE-2026-15100
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all …
No fix yet
MEDIUM 6.4
CVE-2025-9205
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien…
No fix yet
MEDIUM 5.4
CVE-2026-15968
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer.
This issue affects M…
Moveit Transfer
2025.1.5 / 2026.0.3+
MEDIUM 5.1
CVE-2026-65763
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vul…
No fix yet