Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-8887 The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8891 The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8894 The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and incl… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8897 The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8898 The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including,… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8867 The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versi… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8868 The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, an… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8869 The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and in… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8870 The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8871 The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and incl… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8872 The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8873 The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8837 The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8842 The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and incl… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8844 The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including,… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8845 The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and inc… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8846 The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. Th… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8847 The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insuffi… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8866 The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8048 The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shor… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8698 The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insuffic… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8701 The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-tick… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8702 The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortco… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8703 The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.1 CVE-2026-8707 The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-8040 The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all… Mitigation only Fix from $1,6002026-05-27 HIGH 7.1 CVE-2026-6268 The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX han… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.4 CVE-2026-6287 The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId… Mitigation only Fix from $1,6002026-05-27 MEDIUM 5.7 CVE-2026-48999 Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such m… No fix yet Fix from $1,6002026-05-27 MEDIUM 6.4 CVE-2026-9022 The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and incl… No fix yet Fix from $1,6002026-05-27