Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
CRITICAL 9.0 CVE-2026-73044 SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribu… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73050 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73041 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject ma… No fix yet Fix from $5,7502026-08-15 MEDIUM 5.4 CVE-2026-14230 The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a … Fix unknown Fix from $4,0002026-08-15 MEDIUM 6.4 CVE-2026-17090 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module '… No fix yet Fix from $4,0002026-08-15 HIGH 7.2 CVE-2026-16145 The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ac… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.4 CVE-2026-15948 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' … No fix yet Fix from $4,0002026-08-15 HIGH 7.2 CVE-2026-13360 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' param… No fix yet Fix from $4,9002026-08-15 HIGH 7.2 CVE-2026-14433 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_i… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.3 CVE-2026-17209 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. No fix yet Fix from $4,0002026-08-14 HIGH 8.5 CVE-2026-63361 LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.3 CVE-2026-53472 A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to sto… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.4 CVE-2026-72832 Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Co… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.4 CVE-2026-72821 Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the… No fix yet Fix from $4,0002026-08-14 HIGH 7.2 CVE-2026-19794 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input s… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.8 CVE-2026-14290 The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribut… No fix yet Fix from $4,0002026-08-14 HIGH 7.2 CVE-2026-18109 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.… No fix yet Fix from $4,9002026-08-14 HIGH 8.6 CVE-2026-73417 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-56858 Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially lead… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.1 CVE-2026-73531 django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScrip… No fix yet Fix from $4,0002026-08-13 HIGH 8.6 CVE-2026-49864 wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download … No fix yet Fix from $4,9002026-08-13 HIGH 8.2 CVE-2026-73650 SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-73038 NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.1 CVE-2026-73037 Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.1 CVE-2026-73648 rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restrict… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.1 CVE-2026-73572 In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insuff… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.1 CVE-2026-19744 Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the ap… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-28154 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerc… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-73357 Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-73340 Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. No fix yet Fix from $4,0002026-08-13