Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.9 CVE-2026-75529 Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint v… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.1 CVE-2026-67925 Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.1 CVE-2026-63670 ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through pack… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.1 CVE-2026-50771 Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification… Fix unknown Fix from $4,0002026-08-17 HIGH 8.1 CVE-2026-33437 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/… Fix unknown Fix from $4,9002026-08-17 HIGH 8.2 CVE-2026-75048 In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.3 CVE-2026-55674 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single… Fix unknown Fix from $5,7502026-08-17 HIGH 7.3 CVE-2026-13202 A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. Fix unknown Fix from $4,9002026-08-17 HIGH 7.2 CVE-2026-74998 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.4 CVE-2026-74999 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.0 CVE-2026-74800 SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si… Fix unknown Fix from $5,7502026-08-17 HIGH 7.2 CVE-2026-10734 The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and includi… No fix yet Fix from $4,9002026-08-16 HIGH 7.2 CVE-2026-13424 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_u… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.4 CVE-2026-2357 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.1 CVE-2026-19712 The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instru… Fix unknown Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-16758 The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and includin… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-16775 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Sho… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-18402 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Bl… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.4 CVE-2026-13712 The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attribu… Fix unknown Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15604 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_co… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15790 The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15726 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and inclu… No fix yet Fix from $4,0002026-08-16 HIGH 7.2 CVE-2026-15002 The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.1 CVE-2026-15009 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15066 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-11780 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit… No fix yet Fix from $4,0002026-08-16 CRITICAL 9.0 CVE-2026-73052 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73053 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73042 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open … No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73043 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go temp… No fix yet Fix from $5,7502026-08-15