Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 8.5 CVE-2026-46686 Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php … No fix yet Fix from $1,9502026-07-16 MEDIUM 5.4 CVE-2026-63081 Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated att… No fix yet Fix from $1,6002026-07-16 HIGH 7.2 CVE-2026-7543 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 d… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.4 CVE-2026-15021 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including,… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-15099 The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and includ… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-13755 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-12869 The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import… No fix yet Fix from $1,6002026-07-16 HIGH 7.1 CVE-2026-12978 The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its p… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.1 CVE-2026-11371 The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the featu… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-15306 The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … No fix yet Fix from $1,6002026-07-16 HIGH 7.2 CVE-2026-13042 The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 … No fix yet Fix from $1,9502026-07-16 MEDIUM 6.4 CVE-2026-15652 The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Blo… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-14987 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.6 CVE-2026-54458 WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin.… Patch available Fix from $2,3002026-07-15 MEDIUM 6.1 CVE-2026-50182 WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI… Patch available Fix from $1,6002026-07-15 HIGH 7.7 CVE-2026-49279 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in … Patch available Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-26719 Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request contain… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.3 CVE-2026-49867 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit … Patch available Fix from $1,6002026-07-15 HIGH 8.7 CVE-2026-45738 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write ac… Argo Cd 3.2.12 / 3.3.10+ Fix from $1,9502026-07-15 CRITICAL 9.6 CVE-2026-62948 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh… Openwrt 25.12.5+ Fix from $2,3002026-07-15 CRITICAL 9.0 CVE-2026-62378 RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/prev… Patch available Fix from $2,3002026-07-15 MEDIUM 5.5 CVE-2026-9007 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected … Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.1 CVE-2026-41580 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf en… Stirling Pdf 2.0.0+ Fix from $1,6002026-07-15 MEDIUM 6.1 CVE-2026-61453 Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page cont… Mitigation only Fix from $1,6002026-07-15 HIGH 8.6 CVE-2026-57833 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate… Mitigation only Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-58077 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-47730 Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() in… Twig 3.26.0+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-46637 Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe =>… Twig 3.26.0+ Fix from $1,6002026-07-14 MEDIUM 5.0 CVE-2026-42447 jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java… Jadx 1.5.6+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-49978 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow c… Dompurify 3.4.7+ Fix from $1,6002026-07-14