Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-21825 HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute a… Digital Experience Compose Mitigation only Fix from $1,6002026-06-05 MEDIUM 5.4 CVE-2026-50591 In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences. Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.4 CVE-2026-50592 In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view). Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-11273 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engag… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-11186 Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.8 CVE-2026-11166 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2026-11150 Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 7.6 CVE-2026-41518 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In versions 4.9.0 thro… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2025-65640 Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanit… Mitigation only Fix from $1,6002026-06-04 HIGH 7.1 CVE-2025-67448 The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input… Mitigation only Fix from $1,9502026-06-04 HIGH 8.9 CVE-2026-43984 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated u… Mitigation only Fix from $1,9502026-06-04 MEDIUM 5.4 CVE-2019-25742 WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious… No fix yet Fix from $1,6002026-06-04 MEDIUM 5.4 CVE-2019-25743 WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scrip… No fix yet Fix from $1,6002026-06-04 MEDIUM 5.4 CVE-2019-25744 WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts… No fix yet Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2019-25737 Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts thro… No fix yet Fix from $1,6002026-06-04 MEDIUM 5.4 CVE-2019-25739 GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code… No fix yet Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2019-25731 Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submit… No fix yet Fix from $1,6002026-06-04 MEDIUM 5.1 CVE-2026-42840 An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering … Mitigation only Fix from $1,6002026-06-03 MEDIUM 5.4 CVE-2026-26378 Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice fe… Koha after 25.11.00 Fix from $1,6002026-06-03 MEDIUM 6.3 CVE-2026-39107 A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or enco… Mitigation only Fix from $1,6002026-06-03 MEDIUM 6.1 CVE-2026-20233 A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-sit… Webex Meetings Mitigation only Fix from $1,6002026-06-03 HIGH 8.4 CVE-2026-42321 GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS paylo… Mitigation only Fix from $1,9502026-06-03 CRITICAL 9.0 CVE-2026-36748 RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile. Mitigation only Fix from $2,3002026-06-03 MEDIUM 5.1 CVE-2022-31114 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom adm… Mitigation only Fix from $1,6002026-06-03 MEDIUM 5.1 CVE-2026-47324 ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objec… Mitigation only Fix from $1,6002026-06-03 MEDIUM 5.4 CVE-2025-14773 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus:… T Mac Plus Mitigation only Fix from $1,6002026-06-03 HIGH 7.1 CVE-2025-15654 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This i… Mitigation only Fix from $1,9502026-06-03 HIGH 7.1 CVE-2026-40108 GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. Th… Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.1 CVE-2026-35212 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to X… Opencti 7.260227.0+ Fix from $1,6002026-06-02 CRITICAL 9.3 CVE-2026-42849 authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow … Authentik 2025.12.5 / 2026.2.3+ Fix from $2,3002026-06-02