Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-45465
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45453
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 6.1
CVE-2026-42573
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on e…
Svelte
5.55.7+
MEDIUM 6.1
CVE-2026-42599
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event han…
Svelte
5.55.7+
HIGH 8.4
CVE-2026-41098
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spo…
Azure Stack Edge
3.3.2604.3097+
MEDIUM 5.4
CVE-2026-34692
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attac…
Experience Manager
6.5.25.0 / 2026.5.0+
MEDIUM 6.1
CVE-2026-33113
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.1
CVE-2026-47348
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without san…
Patch available
HIGH 8.7
CVE-2026-41031
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker…
Mitigation only
MEDIUM 6.4
CVE-2026-8599
The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…
Mitigation only
MEDIUM 6.4
CVE-2026-8677
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Wid…
Mitigation only
MEDIUM 5.4
CVE-2026-34033
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: thro…
Answer
2.0.1+
MEDIUM 6.1
CVE-2026-41539
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit …
Qts
Mitigation only
MEDIUM 6.4
CVE-2026-8977
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in version…
Mitigation only
MEDIUM 6.4
CVE-2026-8895
The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and …
Mitigation only
MEDIUM 6.4
CVE-2026-7662
The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed…
Mitigation only
MEDIUM 6.4
CVE-2026-8841
The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribut…
Mitigation only
MEDIUM 6.4
CVE-2026-8880
The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the r…
Mitigation only
MEDIUM 6.4
CVE-2026-8882
The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …
Mitigation only
MEDIUM 6.4
CVE-2026-8883
The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up t…
Mitigation only
MEDIUM 6.1
CVE-2026-41845
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting …
Spring Framework
5.3.49 / 6.1.28+
MEDIUM 6.1
CVE-2026-41846
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTM…
Spring Framework
5.3.49 / 6.1.28+
MEDIUM 6.1
CVE-2026-11603
The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in…
Mitigation only
MEDIUM 6.4
CVE-2026-10024
The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to,…
Mitigation only
MEDIUM 6.4
CVE-2026-10738
The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all version…
Mitigation only
MEDIUM 6.4
CVE-2026-5714
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, an…
Mitigation only
HIGH 7.2
CVE-2026-7556
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and incl…
Mitigation only
MEDIUM 6.4
CVE-2026-10862
The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2…
No fix yet
MEDIUM 6.1
CVE-2026-44746
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL …
Mitigation only
HIGH 7.0
CVE-2026-44541
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.j…
Patch available