Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.2 CVE-2026-7517 The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' param… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-2387 The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to th… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-13015 The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, … Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-13246 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-13443 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in… Mitigation only Fix from $1,6002026-07-01 HIGH 7.2 CVE-2026-13731 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conv… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-12135 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute i… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-11380 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-57963 An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the ch… Thunderbird 140.12.1 / 152.0.1+ Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-56356 n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html l… N8n 1.123.27 / 2.13.3+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-50040 Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An … Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-14147 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-14145 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-14068 Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in sp… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-14000 Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-14001 Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2026-13977 Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXS… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-13836 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2026-10585 A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary Ja… Enterprise Server 3.16.20 / 3.17.17+ Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-11594 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $1,6002026-06-30 MEDIUM 6.4 CVE-2025-36320 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2025-36323 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.3 CVE-2026-11708 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-11712 IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-06-30 HIGH 7.2 CVE-2026-10513 The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' an… Mitigation only Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-48307 ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this … Coldfusion Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.1 CVE-2026-8403 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer In… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-52760 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. … Activemq 5.19.8 / 6.2.7+ Fix from $1,6002026-06-30 HIGH 7.2 CVE-2026-8141 The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all v… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.1 CVE-2026-6954 Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or i… Mitigation only Fix from $1,6002026-06-30