Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-57379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Sto… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57380 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-le… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57381 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows … Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57382 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-li… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57383 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57387 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue aff… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57368 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Refle… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57369 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allow… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57376 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Eleme… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57363 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57365 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for As… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.1 CVE-2026-57829 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an un… Helix Ultimate after 2.2.6 Fix from $1,6002026-07-13 MEDIUM 6.1 CVE-2026-15552 Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject per… Mitigation only Fix from $1,6002026-07-13 HIGH 8.8 CVE-2026-61875 luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortM… Mitigation only Fix from $1,9502026-07-12 HIGH 8.8 CVE-2026-61876 LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML ma… Mitigation only Fix from $1,9502026-07-12 MEDIUM 6.4 CVE-2026-1382 The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and i… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-15010 The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Addit… Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-6939 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all … Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.4 CVE-2026-12126 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post… Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-13378 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all ve… Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.4 CVE-2026-15096 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and i… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-15097 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, … Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2025-13968 The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboar… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-5743 The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and… Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-13114 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Us… Mitigation only Fix from $1,9502026-07-11 CRITICAL 9.8 CVE-2026-11913 vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. No fix yet Fix from $2,3002026-07-10 MEDIUM 6.1 CVE-2026-58588 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scriptin… Drupal Canvas 1.4.2 / 1.5.2+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-58591 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XS… Colorbox 2.1.5+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-58587 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scriptin… Drupal Canvas 1.4.2 / 1.5.2+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-55808 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10