Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-68567 Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-66643 Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66644 Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66645 Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66646 Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-66667 Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-66636 Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66637 Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66638 Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66639 Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66640 Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66641 Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-66621 Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-66629 Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-66633 Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-45733 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #ic… Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-32547 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-32333 Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-28568 Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-28569 Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-75838 DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache… Fix unknown Fix from $4,0002026-08-18 HIGH 7.6 CVE-2026-75831 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement met… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75834 Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). … Fix unknown Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-75828 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75107 Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la… Fix unknown Fix from $4,0002026-08-18 HIGH 8.6 CVE-2026-74902 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-75626 SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject … Fix unknown Fix from $5,7502026-08-18 MEDIUM 5.4 CVE-2026-19447 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO… Fix unknown Fix from $4,0002026-08-18 HIGH 7.2 CVE-2026-75091 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… Fix unknown Fix from $4,9002026-08-18 HIGH 7.0 CVE-2026-75531 Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an an… Fix unknown Fix from $4,9002026-08-17