Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.1
CVE-2026-65762
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XS…
No fix yet
HIGH 8.7
CVE-2026-47743
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da…
Patch available
MEDIUM 6.1
CVE-2026-65697
Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attac…
No fix yet
MEDIUM 5.4
CVE-2026-48536
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated a…
No fix yet
MEDIUM 5.4
CVE-2026-48537
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated …
No fix yet
MEDIUM 5.4
CVE-2026-48538
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated…
No fix yet
MEDIUM 5.4
CVE-2026-48539
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authent…
No fix yet
MEDIUM 5.4
CVE-2026-48530
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated at…
No fix yet
MEDIUM 5.4
CVE-2026-48531
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attack…
No fix yet
MEDIUM 5.4
CVE-2026-48532
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authent…
No fix yet
MEDIUM 5.4
CVE-2026-48534
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers t…
No fix yet
MEDIUM 5.4
CVE-2026-48535
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated …
No fix yet
MEDIUM 6.1
CVE-2026-65914
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wra…
Dompurify
3.3.2+
MEDIUM 6.1
CVE-2026-65911
In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HA…
Dompurify
3.4.0+
MEDIUM 6.1
CVE-2026-65912
DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.at…
Dompurify
3.3.2+
MEDIUM 6.1
CVE-2026-65901
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form node…
Dompurify
3.4.7+
HIGH 7.2
CVE-2026-65898
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to p…
Dompurify
3.4.11+
MEDIUM 6.1
CVE-2026-65900
DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT…
Dompurify
3.4.8+
MEDIUM 5.9
CVE-2026-65550
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
No fix yet
CRITICAL 9.6
CVE-2026-65605
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren…
Patch available
CRITICAL 9.6
CVE-2026-65606
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references …
Patch available
MEDIUM 6.5
CVE-2026-65533
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
No fix yet
MEDIUM 5.9
CVE-2026-65534
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
No fix yet
MEDIUM 5.9
CVE-2026-65538
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65522
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65527
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65528
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
No fix yet
HIGH 7.1
CVE-2026-65510
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
No fix yet
HIGH 7.1
CVE-2026-65511
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65514
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
No fix yet