Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-9971 Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in speci… Chrome 148.0.7778.216+ Fix from $1,6002026-05-28 HIGH 8.5 CVE-2026-45343 LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a… Mitigation only Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-44657 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF… Patch available Fix from $1,9502026-05-28 HIGH 8.6 CVE-2026-44655 Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which… Patch available Fix from $1,9502026-05-28 MEDIUM 5.3 CVE-2026-41897 Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target parameter on return_dynamic_… Patch available Fix from $1,6002026-05-28 MEDIUM 5.4 CVE-2026-42401 Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elas… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 MEDIUM 5.0 CVE-2026-43979 Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HT… Patch available Fix from $1,6002026-05-28 CRITICAL 9.6 CVE-2026-45323 MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-… Meshcore Card 0.3.3+ Fix from $2,3002026-05-28 HIGH 8.7 CVE-2026-45348 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes… Mitigation only Fix from $1,9502026-05-28 MEDIUM 5.4 CVE-2026-47759 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attribu… Tinymce 5.11.1 / 7.9.3+ Fix from $1,6002026-05-28 MEDIUM 5.4 CVE-2026-47760 TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope … Tinymce 7.1.0+ Fix from $1,6002026-05-28 MEDIUM 5.4 CVE-2026-47761 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can… Tinymce 5.11.1 / 7.9.3+ Fix from $1,6002026-05-28 MEDIUM 5.4 CVE-2026-47762 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments.… Tinymce 5.11.1 / 7.9.3+ Fix from $1,6002026-05-28 MEDIUM 6.4 CVE-2026-4334 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all … Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.1 CVE-2024-47097 Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code v… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.1 CVE-2024-47096 Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code v… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.3 CVE-2026-9806 A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to the patched release. Notific… Patch available Fix from $1,6002026-05-28 MEDIUM 6.1 CVE-2026-7660 The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and includ… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.4 CVE-2026-6427 The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex… Mitigation only Fix from $1,6002026-05-28 HIGH 7.2 CVE-2026-7052 The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' … Mitigation only Fix from $1,9502026-05-28 HIGH 7.2 CVE-2026-7634 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and inclu… Patch available Fix from $1,9502026-05-28 MEDIUM 6.4 CVE-2026-9644 The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortc… Mitigation only Fix from $1,6002026-05-28 HIGH 7.2 CVE-2026-2374 The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all ve… Mitigation only Fix from $1,9502026-05-28 HIGH 8.7 CVE-2026-42197 RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulner… Patch available Fix from $1,9502026-05-27 MEDIUM 5.4 CVE-2026-42877 FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists … Mitigation only Fix from $1,6002026-05-27 HIGH 8.1 CVE-2026-48149 Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) strai… Mitigation only Fix from $1,9502026-05-27 HIGH 7.6 CVE-2026-46426 Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.4 CVE-2026-38931 A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.1 CVE-2026-49102 Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml i… Patch available Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2026-48927 Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploita… Buildgraph View after 1.8 Fix from $1,6002026-05-27