Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-45465 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45453 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-42573 Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on e… Svelte 5.55.7+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-42599 Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event han… Svelte 5.55.7+ Fix from $1,6002026-06-09 HIGH 8.4 CVE-2026-41098 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spo… Azure Stack Edge 3.3.2604.3097+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-34692 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac… Experience Manager 6.5.25.0 / 2026.5.0+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-33113 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.1 CVE-2026-47348 Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without san… Patch available Fix from $1,6002026-06-09 HIGH 8.7 CVE-2026-41031 A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker… Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.4 CVE-2026-8599 The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8677 The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Wid… Mitigation only Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-34033 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41539 A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit … Qts Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8977 The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in version… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8895 The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and … Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-7662 The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8841 The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribut… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8880 The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the r… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8882 The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, … Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-8883 The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up t… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41845 Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting … Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41846 Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTM… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-11603 The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-10024 The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to,… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-10738 The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all version… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.4 CVE-2026-5714 The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, an… Mitigation only Fix from $1,6002026-06-09 HIGH 7.2 CVE-2026-7556 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and incl… Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.4 CVE-2026-10862 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2… No fix yet Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-44746 Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL … Mitigation only Fix from $1,6002026-06-09 HIGH 7.0 CVE-2026-44541 Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.j… Patch available Fix from $1,9502026-06-08