Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.1 CVE-2026-65762 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XS… No fix yet Fix from $1,6002026-07-23 HIGH 8.7 CVE-2026-47743 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da… Patch available Fix from $1,9502026-07-23 MEDIUM 6.1 CVE-2026-65697 Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attac… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48536 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated a… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48537 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated … No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48538 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48539 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authent… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48530 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated at… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48531 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attack… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48532 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authent… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48534 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers t… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.4 CVE-2026-48535 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.1 CVE-2026-65914 DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wra… Dompurify 3.3.2+ Fix from $1,6002026-07-23 MEDIUM 6.1 CVE-2026-65911 In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HA… Dompurify 3.4.0+ Fix from $1,6002026-07-23 MEDIUM 6.1 CVE-2026-65912 DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.at… Dompurify 3.3.2+ Fix from $1,6002026-07-23 MEDIUM 6.1 CVE-2026-65901 DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form node… Dompurify 3.4.7+ Fix from $1,6002026-07-23 HIGH 7.2 CVE-2026-65898 DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to p… Dompurify 3.4.11+ Fix from $1,9502026-07-23 MEDIUM 6.1 CVE-2026-65900 DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT… Dompurify 3.4.8+ Fix from $1,6002026-07-23 MEDIUM 5.9 CVE-2026-65550 Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. No fix yet Fix from $1,6002026-07-23 CRITICAL 9.6 CVE-2026-65605 SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren… Patch available Fix from $2,3002026-07-23 CRITICAL 9.6 CVE-2026-65606 SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references … Patch available Fix from $2,3002026-07-23 MEDIUM 6.5 CVE-2026-65533 Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.9 CVE-2026-65534 Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.9 CVE-2026-65538 Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-65522 Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-65527 Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-65528 Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.1 CVE-2026-65510 Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-65511 Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-65514 Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. No fix yet Fix from $1,6002026-07-23