Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-3639 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in a… No fix yet Fix from $4,0002026-08-13 HIGH 7.2 CVE-2026-18146 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-73422 Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animatio… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73415 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4… No fix yet Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-73329 CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.4 CVE-2026-72787 Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-49466 Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (X… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-19657 ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visitin… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-18099 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-cont… I No fix yet Fix from $4,0002026-08-12 HIGH 8.7 CVE-2026-15216 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … No fix yet Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-15217 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … No fix yet Fix from $4,9002026-08-12 HIGH 7.7 CVE-2026-16627 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-73295 Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/temp… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-48550 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An u… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-48552 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string value… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-16694 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr… I No fix yet Fix from $4,0002026-08-12 HIGH 8.0 CVE-2026-65937 In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. No fix yet Fix from $4,9002026-08-12 MEDIUM 6.1 CVE-2026-73374 A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tag… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-73262 Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_… No fix yet Fix from $4,0002026-08-12 HIGH 8.9 CVE-2026-57858 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows a… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-70560 Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attacke… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-19217 The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, w… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-17013 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block,… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-16066 The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowin… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-15249 The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing use… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-9318 tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitra… No fix yet Fix from $4,0002026-08-12 HIGH 8.7 CVE-2026-73031 telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browser… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.1 CVE-2026-66146 Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker … No fix yet Fix from $4,0002026-08-11 HIGH 8.7 CVE-2026-48413 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-48414 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… No fix yet Fix from $4,9002026-08-11