Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.4
CVE-2026-45797
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG fil…
Patch available
CRITICAL 9.0
CVE-2026-35198
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a l…
Patch available
MEDIUM 6.9
CVE-2026-59238
Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maa…
Patch available
HIGH 8.7
CVE-2026-45270
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` …
No fix yet
MEDIUM 6.1
CVE-2026-2445
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi…
Api Control Plane
4.2.0.195 / 4.3.0.106+
HIGH 7.1
CVE-2026-9833
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters b…
No fix yet
HIGH 7.1
CVE-2026-12970
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cr…
No fix yet
HIGH 7.5
CVE-2026-12592
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analyti…
No fix yet
HIGH 8.8
CVE-2026-10081
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API befor…
No fix yet
MEDIUM 5.4
CVE-2026-45138
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to saniti…
No fix yet
MEDIUM 5.4
CVE-2026-12228
A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint …
Lollms
after 2.1.0
HIGH 8.7
CVE-2026-54498
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewCompon…
View Component
4.12.0+
CRITICAL 9.3
CVE-2026-15091
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…
Engineering Ai Hub
1.3.0+
HIGH 7.0
CVE-2026-9588
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template fun…
No fix yet
HIGH 8.6
CVE-2026-9585
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application f…
Mitigation only
MEDIUM 5.4
CVE-2026-49216
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX …
Ux
2.36.0+
MEDIUM 6.1
CVE-2026-49210
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::cre…
Ux
2.36.0+
HIGH 8.7
CVE-2026-58148
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to…
No fix yet
MEDIUM 6.1
CVE-2026-51081
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows att…
No fix yet
MEDIUM 6.1
CVE-2026-10525
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the ad…
No fix yet
MEDIUM 6.1
CVE-2026-15094
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, an…
No fix yet
MEDIUM 6.4
CVE-2026-15161
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due…
No fix yet
MEDIUM 6.4
CVE-2026-15759
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting…
No fix yet
MEDIUM 6.1
CVE-2026-11324
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'red…
No fix yet
HIGH 7.2
CVE-2026-15395
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field …
No fix yet
MEDIUM 6.4
CVE-2026-2594
The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to ins…
No fix yet
MEDIUM 6.1
CVE-2026-58643
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo…
Windows Admin Center
2511+
MEDIUM 5.4
CVE-2026-62826
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20434+
HIGH 8.4
CVE-2026-45368
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image block…
Mitigation only
HIGH 8.5
CVE-2026-44175
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list fie…
No fix yet