Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-39540 Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-39514 Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-39507 Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.5 CVE-2026-39491 Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-39449 Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.3 CVE-2026-39451 Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.1 CVE-2026-39463 Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-34900 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions. No fix yet Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-34902 Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-39435 Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-39447 Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2026-23970 Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2025-68840 Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2025-68851 Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2025-68872 Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.6 CVE-2026-50883 An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a craft… Mitigation only Fix from $2,3002026-06-15 MEDIUM 5.4 CVE-2026-50876 A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.1 CVE-2026-37216 Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.1 CVE-2026-36521 PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module. Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.1 CVE-2026-49294 Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to refl… Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2025-15659 Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions. No fix yet Fix from $1,6002026-06-15 MEDIUM 5.9 CVE-2025-15658 Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.2 CVE-2016-20084 WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify c… No fix yet Fix from $1,9502026-06-15 MEDIUM 6.4 CVE-2016-20070 WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated… No fix yet Fix from $1,6002026-06-15 HIGH 7.2 CVE-2016-20066 WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitiz… No fix yet Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-5513 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-custo… No fix yet Fix from $1,9502026-06-13 MEDIUM 6.4 CVE-2026-3297 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in… Mitigation only Fix from $1,6002026-06-13 MEDIUM 6.4 CVE-2026-9629 The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due … Mitigation only Fix from $1,6002026-06-13 MEDIUM 6.4 CVE-2026-9134 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to… Mitigation only Fix from $1,6002026-06-13 HIGH 7.2 CVE-2026-9109 The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site… Mitigation only Fix from $1,9502026-06-13