Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-57617 Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-57618 Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.1 CVE-2026-57314 Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-57317 Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-57319 Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-57322 Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56072 Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-57312 Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-57313 Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.1 CVE-2026-56041 Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56043 Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56044 Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56045 Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-56046 Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.1 CVE-2026-56047 Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56039 Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56040 Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56011 Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2025-68074 Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2025-68075 Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-57620 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows … Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-6658 A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML expor… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-50740 A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user … Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-50742 A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue … Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 6.1 CVE-2026-50745 A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follo… Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 6.9 CVE-2026-13083 A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at… Pen Drive 1.0.0-2+ Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2020-37256 Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users wit… Grav 1.6.30+ Fix from $1,6002026-06-25 HIGH 7.3 CVE-2026-9086 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 MEDIUM 5.4 CVE-2026-54025 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown arti… Librechat after 0.7.8 Fix from $1,6002026-06-25 MEDIUM 6.1 CVE-2026-48942 K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. K2 after 2.26 Fix from $1,6002026-06-25