Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-57427 Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-57428 Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-27403 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This … No fix yet Fix from $1,6002026-07-23 MEDIUM 5.9 CVE-2026-24628 Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 5.9 CVE-2025-68081 Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.1 CVE-2026-65756 Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15794 The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versio… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15394 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15404 The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15646 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, a… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-14481 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Script… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-9635 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-9729 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr… No fix yet Fix from $1,6002026-07-23 HIGH 7.2 CVE-2026-12421 The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.1 CVE-2026-9066 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to… No fix yet Fix from $1,6002026-07-23 HIGH 7.2 CVE-2026-7232 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and inclu… No fix yet Fix from $1,9502026-07-23 HIGH 7.2 CVE-2026-7534 The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.4 CVE-2026-64795 Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.1 CVE-2026-64828 Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML… No fix yet Fix from $1,6002026-07-22 CRITICAL 9.3 CVE-2026-8152 Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is dep… No fix yet Fix from $2,3002026-07-22 MEDIUM 5.4 CVE-2026-65592 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the … N8n 1.123.64 / 2.29.8+ Fix from $1,6002026-07-22 MEDIUM 5.4 CVE-2026-65597 n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders … N8n 1.123.64 / 2.29.8+ Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-63264 Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vu… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.4 CVE-2026-15787 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-… No fix yet Fix from $1,6002026-07-22 HIGH 8.8 CVE-2026-12968 The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint a… No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60664 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.0 CVE-2026-60646 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.0 CVE-2026-60650 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60634 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60635 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21