Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.2 CVE-2026-9643 The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.4 CVE-2026-9620 The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.1 CVE-2026-8628 The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.4 CVE-2026-8865 The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.4 CVE-2026-8896 The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such … Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.1 CVE-2026-8622 The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, an… Mitigation only Fix from $1,6002026-06-24 HIGH 7.2 CVE-2026-10091 The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to… Mitigation only Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-10092 The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all v… Mitigation only Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-3652 The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX a… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.4 CVE-2026-11614 The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter … Mitigation only Fix from $1,6002026-06-24 HIGH 8.2 CVE-2026-56785 FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without pr… Patch available Fix from $1,9502026-06-23 MEDIUM 5.1 CVE-2026-53929 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authenticated uploader could deliv… Mitigation only Fix from $1,6002026-06-23 HIGH 7.4 CVE-2026-47383 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HTML in row comments that execu… Mitigation only Fix from $1,9502026-06-23 HIGH 8.4 CVE-2026-47387 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (packages/nc-gui/composables/useSh… Mitigation only Fix from $1,9502026-06-23 MEDIUM 5.1 CVE-2026-47376 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScr… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-46547 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning page.… Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-54011 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks f… Open Webui 0.9.6+ Fix from $1,6002026-06-23 HIGH 7.6 CVE-2026-54013 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user… Open Webui 0.9.6+ Fix from $1,9502026-06-23 CRITICAL 9.6 CVE-2026-53662 immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X… Patch available Fix from $2,3002026-06-23 MEDIUM 5.4 CVE-2026-54301 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could conf… N8n 1.123.55 / 2.25.7+ Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-54302 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inje… N8n 1.123.55 / 2.25.7+ Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-34915 A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit… Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-54303 n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query param… N8n 2.24.0+ Fix from $1,6002026-06-23 MEDIUM 5.1 CVE-2026-11772 DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arb… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-56263 Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via in… Crawl4ai 0.8.7+ Fix from $1,6002026-06-23 MEDIUM 6.4 CVE-2026-4610 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message'… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-10857 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry a… Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.4 CVE-2026-4983 Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without … Open Vsx 0.34.1+ Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-56698 Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side scrip… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-22 HIGH 7.6 CVE-2026-55409 Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered … Mitigation only Fix from $1,9502026-06-22