Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.4
CVE-2026-6742
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and inclu…
Mitigation only
MEDIUM 6.4
CVE-2025-14785
The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Store…
Mitigation only
MEDIUM 6.1
CVE-2026-11798
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via…
Mitigation only
MEDIUM 6.4
CVE-2026-10570
The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versi…
Mitigation only
MEDIUM 5.4
CVE-2026-55437
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `Ag…
Coder
2.29.17 / 2.32.7+
MEDIUM 5.4
CVE-2026-36162
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbi…
Mitigation only
MEDIUM 5.4
CVE-2026-36163
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the…
Mitigation only
MEDIUM 5.1
CVE-2026-55647
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue…
Patch available
MEDIUM 6.1
CVE-2026-48954
Improper validation leads to a generic XSS vector in the language override feature.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48949
Lack of validation leads to an XSS vulnerability in the MFA management views.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48950
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48951
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48952
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48953
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.5
CVE-2025-12799
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped ch…
Mitigation only
MEDIUM 5.4
CVE-2026-8309
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access…
Mitigation only
MEDIUM 6.1
CVE-2026-8306
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access…
Mitigation only
MEDIUM 6.4
CVE-2026-11328
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up …
Mitigation only
MEDIUM 6.1
CVE-2026-59710
showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properl…
Patch available
MEDIUM 6.1
CVE-2026-59711
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When…
Mitigation only
MEDIUM 5.4
CVE-2026-58402
Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string …
Hugo
0.163.3+
MEDIUM 6.1
CVE-2026-50133
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (ty…
Hugo
0.162.0+
MEDIUM 6.4
CVE-2026-12154
The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attr…
Mitigation only
HIGH 8.2
CVE-2025-53831
DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO fo…
Mitigation only
MEDIUM 6.1
CVE-2025-8591
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c…
Api Control Plane
2.0.0.404 / 2.0.0.424+
MEDIUM 6.1
CVE-2026-58524
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…
Edge Chromium
150.0.4078.48+
MEDIUM 6.1
CVE-2026-58298
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…
Edge Chromium
150.0.4078.48+
HIGH 7.1
CVE-2026-57977
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…
Edge Chromium
150.0.4078.48+
HIGH 8.7
CVE-2026-28737
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file…
Patch available
MEDIUM 6.1
CVE-2026-4322
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertisi…
Mitigation only