Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-12157 The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… Mitigation only Fix from $1,6002026-06-19 MEDIUM 6.4 CVE-2026-1856 The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up… Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.4 CVE-2026-12047 HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /go… Pgadmin 4 9.16+ Fix from $1,6002026-06-19 MEDIUM 5.4 CVE-2026-12048 Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse message… Pgadmin 4 9.16+ Fix from $1,6002026-06-19 MEDIUM 5.4 CVE-2026-43915 Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerabili… Coturn 4.11.0+ Fix from $1,6002026-06-18 MEDIUM 5.1 CVE-2026-11982 Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow. Patch available Fix from $1,6002026-06-18 MEDIUM 5.9 CVE-2026-56007 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS… Mitigation only Fix from $1,6002026-06-18 MEDIUM 5.9 CVE-2026-56009 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS… Mitigation only Fix from $1,6002026-06-18 MEDIUM 5.1 CVE-2026-54219 UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low p… Mitigation only Fix from $1,6002026-06-18 MEDIUM 5.1 CVE-2026-54221 UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrar… Mitigation only Fix from $1,6002026-06-18 MEDIUM 6.4 CVE-2026-8039 The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' sh… Mitigation only Fix from $1,6002026-06-18 MEDIUM 6.4 CVE-2026-2021 The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions… Mitigation only Fix from $1,6002026-06-18 HIGH 7.6 CVE-2026-55746 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title… Mitigation only Fix from $1,9502026-06-18 MEDIUM 6.4 CVE-2026-12098 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all v… Mitigation only Fix from $1,6002026-06-18 MEDIUM 6.4 CVE-2026-12136 The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode … Mitigation only Fix from $1,6002026-06-18 MEDIUM 6.1 CVE-2026-12137 The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cros… Mitigation only Fix from $1,6002026-06-18 MEDIUM 6.4 CVE-2026-11402 The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link'… Mitigation only Fix from $1,6002026-06-18 CRITICAL 9.3 CVE-2026-48768 TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns… Mitigation only Fix from $2,3002026-06-18 MEDIUM 6.1 CVE-2026-44644 LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a … Patch available Fix from $1,6002026-06-17 MEDIUM 6.1 CVE-2026-54386 marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arb… Patch available Fix from $1,6002026-06-17 MEDIUM 5.8 CVE-2026-48821 Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Sy… Mitigation only Fix from $1,6002026-06-17 MEDIUM 5.8 CVE-2026-48822 Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTM… Mitigation only Fix from $1,6002026-06-17 MEDIUM 5.4 CVE-2026-10850 Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr… Plane No fix yet Fix from $1,6002026-06-17 HIGH 7.1 CVE-2026-40720 Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.1 CVE-2025-69140 Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.1 CVE-2025-68524 Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.4 CVE-2026-8607 The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross… Mitigation only Fix from $1,6002026-06-17 HIGH 7.1 CVE-2026-9570 The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page… Mitigation only Fix from $1,9502026-06-17 MEDIUM 6.4 CVE-2026-8494 The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all… Mitigation only Fix from $1,6002026-06-17 HIGH 7.1 CVE-2026-8089 The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properl… Mitigation only Fix from $1,9502026-06-17