Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-13252 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-S… Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.4 CVE-2026-13704 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction… Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.4 CVE-2026-10089 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to,… Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.9 CVE-2026-55791 Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerab… Patch available Fix from $1,6002026-07-02 HIGH 7.4 CVE-2026-55790 Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub ac… Patch available Fix from $1,9502026-07-01 MEDIUM 5.9 CVE-2026-55793 Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaSc… Patch available Fix from $1,6002026-07-01 HIGH 7.3 CVE-2026-54263 Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS… Wagtail 7.3.3 / 7.4.2+ Fix from $1,9502026-07-01 HIGH 7.2 CVE-2026-58263 Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be … Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.4 CVE-2026-54720 Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in… Mitigation only Fix from $1,6002026-07-01 HIGH 7.6 CVE-2026-55660 Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich… Patch available Fix from $1,9502026-07-01 MEDIUM 6.1 CVE-2026-14358 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Ext… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 5.9 CVE-2026-57722 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored X… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-57737 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Ph… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-58037 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-58038 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vu… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-58028 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedi… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-58030 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeS… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-58032 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-5220 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-6283 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-58031 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v… Mediawiki Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-53907 MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 HIGH 8.7 CVE-2026-13323 In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Sec… Open Vsx 1.0.2+ Fix from $1,9502026-07-01 HIGH 7.2 CVE-2026-12142 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter i… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-10095 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and incl… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-12754 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-12732 The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, … Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-13733 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, a… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-9107 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-58519 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte… Cargo 3.9.1+ Fix from $1,6002026-07-01