Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-6742 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and inclu… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2025-14785 The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Store… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-11798 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-10570 The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versi… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-55437 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `Ag… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-36162 An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbi… Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.4 CVE-2026-36163 An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the… Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.1 CVE-2026-55647 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue… Patch available Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48954 Improper validation leads to a generic XSS vector in the language override feature. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48949 Lack of validation leads to an XSS vulnerability in the MFA management views. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48950 Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48951 Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48952 Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48953 Lack of escaping leads to an XSS vulnerability in the generic image output layout. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2025-12799 A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped ch… Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.4 CVE-2026-8309 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access… Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-8306 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access… Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.4 CVE-2026-11328 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up … Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-59710 showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properl… Patch available Fix from $1,6002026-07-06 MEDIUM 6.1 CVE-2026-59711 showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When… Mitigation only Fix from $1,6002026-07-06 MEDIUM 5.4 CVE-2026-58402 Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string … Hugo 0.163.3+ Fix from $1,6002026-07-06 MEDIUM 6.1 CVE-2026-50133 Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (ty… Hugo 0.162.0+ Fix from $1,6002026-07-06 MEDIUM 6.4 CVE-2026-12154 The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attr… Mitigation only Fix from $1,6002026-07-06 HIGH 8.2 CVE-2025-53831 DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO fo… Mitigation only Fix from $1,9502026-07-06 MEDIUM 6.1 CVE-2025-8591 The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c… Api Control Plane 2.0.0.404 / 2.0.0.424+ Fix from $1,6002026-07-06 MEDIUM 6.1 CVE-2026-58524 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack… Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 MEDIUM 6.1 CVE-2026-58298 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack… Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 HIGH 7.1 CVE-2026-57977 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack… Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 8.7 CVE-2026-28737 Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file… Patch available Fix from $1,9502026-07-03 MEDIUM 6.1 CVE-2026-4322 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertisi… Mitigation only Fix from $1,6002026-07-03