Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 8.7 CVE-2026-53608 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the… Mitigation only Fix from $1,9502026-06-12 MEDIUM 5.1 CVE-2026-54393 A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-contro… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-54395 MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScrip… Patch available Fix from $1,6002026-06-12 MEDIUM 5.4 CVE-2026-53606 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of s… Mitigation only Fix from $1,6002026-06-12 CRITICAL 9.3 CVE-2026-44990 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the def… Mitigation only Fix from $2,3002026-06-12 HIGH 7.3 CVE-2026-45011 ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget… Mitigation only Fix from $1,9502026-06-12 MEDIUM 5.3 CVE-2026-45014 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting … Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-53568 Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List Vi… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.4 CVE-2026-53722 Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-47739 Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization… Mitigation only Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-44205 Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an a… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.4 CVE-2026-46342 Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitr… Nuxt 3.21.6 / 4.4.5+ Fix from $1,6002026-06-12 MEDIUM 6.4 CVE-2026-9125 The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] short… Mitigation only Fix from $1,6002026-06-12 HIGH 7.1 CVE-2026-42653 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This iss… Mitigation only Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-46489 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation.… Patch available Fix from $1,9502026-06-11 HIGH 8.7 CVE-2026-8589 GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that unde… GitLab 18.10.8 / 18.11.5+ Fix from $1,9502026-06-11 HIGH 8.7 CVE-2026-10087 GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under … GitLab 18.10.8 / 18.11.5+ Fix from $1,9502026-06-11 HIGH 7.1 CVE-2023-33999 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This… Mitigation only Fix from $1,9502026-06-11 HIGH 7.6 CVE-2026-42558 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerabi… Mitigation only Fix from $1,9502026-06-10 MEDIUM 5.4 CVE-2026-53740 Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can sche… Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-53741 Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_… Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-53742 Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers … Mitigation only Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-53737 Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the co… Mitigation only Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-46642 draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file can execute arbitrary JavaScrip… Drawio 29.7.12+ Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-20258 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.250… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,6002026-06-10 MEDIUM 6.9 CVE-2026-53693 A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, c… Patch available Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-53473 A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing … Migration Planner Ui 0.13.5+ Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-45560 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/c… Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-53441 Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic… Jenkins 2.555.3 / 2.568+ Fix from $1,6002026-06-10 HIGH 7.1 CVE-2026-49069 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This is… Mitigation only Fix from $1,9502026-06-10