Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-45797 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG fil… Patch available Fix from $1,6002026-07-20 CRITICAL 9.0 CVE-2026-35198 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a l… Patch available Fix from $2,3002026-07-20 MEDIUM 6.9 CVE-2026-59238 Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maa… Patch available Fix from $1,6002026-07-20 HIGH 8.7 CVE-2026-45270 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` … No fix yet Fix from $1,9502026-07-20 MEDIUM 6.1 CVE-2026-2445 The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi… Api Control Plane 4.2.0.195 / 4.3.0.106+ Fix from $1,6002026-07-20 HIGH 7.1 CVE-2026-9833 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters b… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-12970 The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cr… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-12592 The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analyti… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-10081 The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API befor… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-45138 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to saniti… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-12228 A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint … Lollms after 2.1.0 Fix from $1,6002026-07-18 HIGH 8.7 CVE-2026-54498 view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewCompon… View Component 4.12.0+ Fix from $1,9502026-07-17 CRITICAL 9.3 CVE-2026-15091 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur… Engineering Ai Hub 1.3.0+ Fix from $2,3002026-07-17 HIGH 7.0 CVE-2026-9588 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template fun… No fix yet Fix from $1,9502026-07-17 HIGH 8.6 CVE-2026-9585 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application f… Mitigation only Fix from $1,9502026-07-17 MEDIUM 5.4 CVE-2026-49216 Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX … Ux 2.36.0+ Fix from $1,6002026-07-17 MEDIUM 6.1 CVE-2026-49210 Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::cre… Ux 2.36.0+ Fix from $1,6002026-07-17 HIGH 8.7 CVE-2026-58148 Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.1 CVE-2026-51081 A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows att… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.1 CVE-2026-10525 The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the ad… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.1 CVE-2026-15094 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, an… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.4 CVE-2026-15161 The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.4 CVE-2026-15759 The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.1 CVE-2026-11324 The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'red… No fix yet Fix from $1,6002026-07-17 HIGH 7.2 CVE-2026-15395 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field … No fix yet Fix from $1,9502026-07-17 MEDIUM 6.4 CVE-2026-2594 The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to ins… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.1 CVE-2026-58643 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo… Windows Admin Center 2511+ Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-62826 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-16 HIGH 8.4 CVE-2026-45368 Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image block… Mitigation only Fix from $1,9502026-07-16 HIGH 8.5 CVE-2026-44175 Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list fie… No fix yet Fix from $1,9502026-07-16