Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.4
CVE-2026-4804
The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is …
Mitigation only
MEDIUM 6.4
CVE-2026-9756
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in…
Mitigation only
MEDIUM 6.4
CVE-2026-8351
The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in version…
Mitigation only
HIGH 7.2
CVE-2026-9148
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, …
Mitigation only
MEDIUM 6.4
CVE-2026-9626
The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in v…
Mitigation only
MEDIUM 6.4
CVE-2026-8489
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Mitigation only
MEDIUM 6.4
CVE-2026-8892
The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Addre…
Mitigation only
HIGH 7.2
CVE-2026-13040
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter …
Mitigation only
MEDIUM 6.4
CVE-2026-12731
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…
Mitigation only
MEDIUM 6.4
CVE-2026-12734
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…
Mitigation only
MEDIUM 5.4
CVE-2026-59102
Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in oth…
Mitigation only
MEDIUM 5.4
CVE-2026-58579
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via norma…
Patch available
MEDIUM 6.1
CVE-2025-71385
Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generat…
Netdata
2.3.1+
HIGH 7.0
CVE-2026-8699
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insuffi…
Mitigation only
MEDIUM 5.4
CVE-2026-4772
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored …
Mitigation only
MEDIUM 5.9
CVE-2026-57762
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57763
Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57764
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57754
Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57755
Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57684
Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.
No fix yet
HIGH 7.1
CVE-2026-57686
Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
Mitigation only
HIGH 7.1
CVE-2026-57674
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
Mitigation only
HIGH 7.1
CVE-2026-57675
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.
Mitigation only
HIGH 7.1
CVE-2026-57678
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected X…
Mitigation only
HIGH 7.1
CVE-2026-57682
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
Mitigation only
CRITICAL 9.6
CVE-2026-57625
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Mitigation only
HIGH 7.1
CVE-2026-57670
Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
No fix yet
HIGH 7.1
CVE-2026-57671
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.
Mitigation only
HIGH 7.1
CVE-2026-57672
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.
Mitigation only