Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2026-57427
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
No fix yet
HIGH 7.1
CVE-2026-57428
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
No fix yet
MEDIUM 6.5
CVE-2026-27403
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This …
No fix yet
MEDIUM 5.9
CVE-2026-24628
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
No fix yet
MEDIUM 5.9
CVE-2025-68081
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
No fix yet
MEDIUM 6.1
CVE-2026-65756
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
No fix yet
MEDIUM 6.4
CVE-2026-15794
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versio…
No fix yet
MEDIUM 6.4
CVE-2026-15394
The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code…
No fix yet
MEDIUM 6.4
CVE-2026-15404
The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to…
No fix yet
MEDIUM 6.4
CVE-2026-15646
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, a…
No fix yet
MEDIUM 6.4
CVE-2026-14481
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Script…
No fix yet
MEDIUM 6.4
CVE-2026-9635
The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in…
No fix yet
MEDIUM 6.4
CVE-2026-9729
The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr…
No fix yet
HIGH 7.2
CVE-2026-12421
The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1…
No fix yet
MEDIUM 6.1
CVE-2026-9066
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to…
No fix yet
HIGH 7.2
CVE-2026-7232
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and inclu…
No fix yet
HIGH 7.2
CVE-2026-7534
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v…
No fix yet
MEDIUM 5.4
CVE-2026-64795
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content…
No fix yet
MEDIUM 6.1
CVE-2026-64828
Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML…
No fix yet
CRITICAL 9.3
CVE-2026-8152
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.
When Unblu Spark is dep…
No fix yet
MEDIUM 5.4
CVE-2026-65592
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the …
N8n
1.123.64 / 2.29.8+
MEDIUM 5.4
CVE-2026-65597
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders …
N8n
1.123.64 / 2.29.8+
MEDIUM 5.3
CVE-2026-63264
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vu…
No fix yet
MEDIUM 6.4
CVE-2026-15787
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-…
No fix yet
HIGH 8.8
CVE-2026-12968
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint a…
No fix yet
HIGH 8.8
CVE-2026-60664
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.0
CVE-2026-60646
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 8.0
CVE-2026-60650
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60634
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet
HIGH 8.8
CVE-2026-60635
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …
Webcenter Content
No fix yet