Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-4804 The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is … Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-9756 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8351 The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in version… Mitigation only Fix from $1,6002026-07-03 HIGH 7.2 CVE-2026-9148 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, … Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.4 CVE-2026-9626 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in v… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8489 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8892 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Addre… Mitigation only Fix from $1,6002026-07-03 HIGH 7.2 CVE-2026-13040 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter … Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.4 CVE-2026-12731 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-12734 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… Mitigation only Fix from $1,6002026-07-03 MEDIUM 5.4 CVE-2026-59102 Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in oth… Mitigation only Fix from $1,6002026-07-02 MEDIUM 5.4 CVE-2026-58579 RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via norma… Patch available Fix from $1,6002026-07-02 MEDIUM 6.1 CVE-2025-71385 Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generat… Netdata 2.3.1+ Fix from $1,6002026-07-02 HIGH 7.0 CVE-2026-8699 A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insuffi… Mitigation only Fix from $1,9502026-07-02 MEDIUM 5.4 CVE-2026-4772 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored … Mitigation only Fix from $1,6002026-07-02 MEDIUM 5.9 CVE-2026-57762 Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57763 Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57764 Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57754 Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57755 Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions. Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.5 CVE-2026-57684 Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. No fix yet Fix from $1,6002026-07-02 HIGH 7.1 CVE-2026-57686 Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57674 Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57675 Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected X… Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57682 Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.6 CVE-2026-57625 Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. Mitigation only Fix from $2,3002026-07-02 HIGH 7.1 CVE-2026-57670 Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions. No fix yet Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57671 Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57672 Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions. Mitigation only Fix from $1,9502026-07-02