Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-39540
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-39514
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
Mitigation only
HIGH 7.1
CVE-2026-39507
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-39491
Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-39449
Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.
Mitigation only
MEDIUM 6.3
CVE-2026-39451
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
Mitigation only
HIGH 7.1
CVE-2026-39463
Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
Mitigation only
HIGH 7.1
CVE-2026-34900
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
No fix yet
HIGH 7.1
CVE-2026-34902
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
Mitigation only
HIGH 7.1
CVE-2026-39435
Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
Mitigation only
HIGH 7.1
CVE-2026-39447
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
Mitigation only
HIGH 7.1
CVE-2026-23970
Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
Mitigation only
HIGH 7.1
CVE-2025-68840
Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
Mitigation only
HIGH 7.1
CVE-2025-68851
Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
Mitigation only
HIGH 7.1
CVE-2025-68872
Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
Mitigation only
CRITICAL 9.6
CVE-2026-50883
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a craft…
Mitigation only
MEDIUM 5.4
CVE-2026-50876
A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Mitigation only
MEDIUM 6.1
CVE-2026-37216
Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
Mitigation only
MEDIUM 6.1
CVE-2026-36521
PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
Mitigation only
MEDIUM 6.1
CVE-2026-49294
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to refl…
Mitigation only
MEDIUM 6.5
CVE-2025-15659
Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
No fix yet
MEDIUM 5.9
CVE-2025-15658
Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
Mitigation only
HIGH 7.2
CVE-2016-20084
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify c…
No fix yet
MEDIUM 6.4
CVE-2016-20070
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated…
No fix yet
HIGH 7.2
CVE-2016-20066
WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitiz…
No fix yet
HIGH 7.2
CVE-2026-5513
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-custo…
No fix yet
MEDIUM 6.4
CVE-2026-3297
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in…
Mitigation only
MEDIUM 6.4
CVE-2026-9629
The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due …
Mitigation only
MEDIUM 6.4
CVE-2026-9134
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to…
Mitigation only
HIGH 7.2
CVE-2026-9109
The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site…
Mitigation only