Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 8.4 CVE-2026-5385 An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before … Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.1 CVE-2026-30586 Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo … Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-33553 Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.4 CVE-2026-33244 React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization o… React Router 7.13.2+ Fix from $1,6002026-06-02 MEDIUM 5.4 CVE-2026-7299 Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an auth… Appsmith 1.99+ Fix from $1,6002026-06-02 MEDIUM 5.9 CVE-2026-28116 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored … Mitigation only Fix from $1,6002026-06-02 HIGH 7.1 CVE-2026-42685 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This… Mitigation only Fix from $1,9502026-06-02 MEDIUM 5.4 CVE-2026-5191 The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in … Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.1 CVE-2026-34907 Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. … Mitigation only Fix from $1,6002026-06-02 HIGH 7.1 CVE-2025-52759 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XS… Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.4 CVE-2026-4080 The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.4 CVE-2026-4081 The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. Thi… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.4 CVE-2026-8885 The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.5 CVE-2025-5085 The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and includi… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-1450 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-1451 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.4 CVE-2026-2382 The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX ac… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-2425 The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to,… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.4 CVE-2026-3722 The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cros… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.1 CVE-2026-10510 Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versio… Mitigation only Fix from $1,6002026-06-02 HIGH 8.2 CVE-2026-24752 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 MEDIUM 5.4 CVE-2026-24754 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authentic… Kiteworks 9.3.0+ Fix from $1,6002026-06-01 HIGH 8.2 CVE-2026-24751 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-42676 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects m… Mitigation only Fix from $1,6002026-06-01 HIGH 7.1 CVE-2026-42678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based … Mitigation only Fix from $1,9502026-06-01 HIGH 7.1 CVE-2026-48839 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. … Mitigation only Fix from $1,9502026-06-01 HIGH 7.1 CVE-2026-48865 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. Thi… Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.4 CVE-2026-48559 Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScri… Mitigation only Fix from $1,6002026-06-01 HIGH 7.1 CVE-2026-42683 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS … Mitigation only Fix from $1,9502026-06-01 HIGH 7.1 CVE-2026-42681 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This iss… Mitigation only Fix from $1,9502026-06-01