Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-15084 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows St… Ui Patterns 2.0.17+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-15085 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. T… Ai Seo\/geo Analyzer 1.1.3+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-15082 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site … Siteimprove Analytics 2.0.1+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-13231 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_fee… Advanced Content Feedback 2.8+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-13234 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cros… Artificial Intelligence 1.2.17 / 1.3.8+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-10769 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This is… Commerce Core 3.3.6+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-10770 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected … Anti Spam 9.7.1+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-11908 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue aff… Tagify 1.2.52+ Fix from $1,6002026-07-10 MEDIUM 5.7 CVE-2026-57213 RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the cons… Patch available Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-57214 RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument in… Rabbitmq Server 4.2.5+ Fix from $1,6002026-07-10 CRITICAL 9.3 CVE-2026-55879 OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page… Patch available Fix from $2,3002026-07-10 HIGH 7.7 CVE-2026-55659 Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled val… Patch available Fix from $1,9502026-07-10 HIGH 8.5 CVE-2026-55665 Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scripting vulnerabilities where a… Patch available Fix from $1,9502026-07-10 MEDIUM 6.2 CVE-2026-55481 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside … Patch available Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-54714 Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML RelayState, SAMLResponse, … Patch available Fix from $1,6002026-07-10 HIGH 8.7 CVE-2026-55466 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml … Snipe It 8.6.2+ Fix from $1,9502026-07-10 MEDIUM 5.4 CVE-2026-55464 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyp… Snipe It 8.6.2+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2025-30008 HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by … Control Panel 1.9.5+ Fix from $1,6002026-07-10 HIGH 7.3 CVE-2026-56667 ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSe… Patch available Fix from $1,9502026-07-10 MEDIUM 6.4 CVE-2026-3251 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-8595 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the bro… Grafana 12.4.4 / 13.0.2+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-61492 In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible Youtrack 2026.2.17394+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-59794 In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data Teamcity 2026.1.2+ Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-59795 In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible Teamcity 2026.1.2+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-56354 n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form… N8n 1.123.24 / 2.10.4+ Fix from $1,6002026-07-10 HIGH 8.2 CVE-2026-29519 Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.4 CVE-2026-13247 The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-13710 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site … Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.1 CVE-2026-41877 R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the fil… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-9838 The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and inc… Mitigation only Fix from $1,6002026-07-10