Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-8613 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up … Mitigation only Fix from $1,6002026-06-10 MEDIUM 6.4 CVE-2026-9019 The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][att… Mitigation only Fix from $1,6002026-06-10 HIGH 8.8 CVE-2026-8071 The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its ema… Mitigation only Fix from $1,9502026-06-10 MEDIUM 6.4 CVE-2025-8444 The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-S… Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-46546 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user… Learning 2.52.0+ Fix from $1,6002026-06-10 HIGH 8.7 CVE-2026-46518 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-sit… Openemr 8.0.0.1+ Fix from $1,9502026-06-10 MEDIUM 5.4 CVE-2026-41003 An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 MEDIUM 6.1 CVE-2026-25860 OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arb… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-34417 OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's… Mitigation only Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-47933 ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi… Coldfusion Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-34416 OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's… Mitigation only Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-25557 Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter valu… Mitigation only Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-11799 UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. Focus 151.3.1+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-47106 Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search funct… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-32856 Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthentic… Mitigation only Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-36728 A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitr… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-36725 A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute ar… Mitigation only Fix from $1,6002026-06-09 HIGH 8.0 CVE-2026-34693 Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An at… Experience Manager after 6.5.24.0 Fix from $1,9502026-06-09 CRITICAL 9.3 CVE-2026-34691 Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that coul… Experience Manager after 6.5.24.0 Fix from $2,3002026-06-09 MEDIUM 5.4 CVE-2026-48297 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48299 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48300 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48301 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48304 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could b… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48560 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48266 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48268 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48271 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-48280 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-47993 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09