Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-3907 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-12924 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… Mitigation only Fix from $1,6002026-07-10 HIGH 7.2 CVE-2026-15298 The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insu… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.4 CVE-2026-15299 The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' par… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15301 The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, a… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15292 The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode in… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15296 The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_prod… No fix yet Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-15297 The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Sc… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15284 The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, a… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15285 The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-11392 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in … Mitigation only Fix from $1,6002026-07-10 HIGH 8.6 CVE-2026-59833 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engin… Patch available Fix from $1,9502026-07-09 MEDIUM 5.4 CVE-2026-58144 Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbit… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2026-55424 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently no… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2026-53962 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and use… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,6002026-07-09 CRITICAL 9.0 CVE-2026-53963 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-c… Discourse 2026.1.5 / 2026.4.2+ Fix from $2,3002026-07-09 MEDIUM 5.4 CVE-2026-60120 Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to… Patch available Fix from $1,6002026-07-09 HIGH 8.5 CVE-2026-54002 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::… Patch available Fix from $1,9502026-07-09 MEDIUM 6.1 CVE-2026-0279 Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal featu… Pan Os 11.1.16 / 11.2.13+ Fix from $1,6002026-07-09 CRITICAL 9.0 CVE-2026-59214 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodid… Open Webui 0.10.0+ Fix from $2,3002026-07-09 MEDIUM 6.4 CVE-2026-53987 The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::… Patch available Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2026-5005 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-9253 The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' … Mitigation only Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-13441 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_back… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.1 CVE-2026-5793 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticare… Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.3 CVE-2026-2342 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al… Mitigation only Fix from $2,3002026-07-09 MEDIUM 6.4 CVE-2026-6910 The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `h… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-4653 The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up t… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-14343 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-15000 The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all ve… Mitigation only Fix from $1,9502026-07-09