Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.5 CVE-2026-40607 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect e… Patch available Fix from $1,9502026-05-22 HIGH 8.5 CVE-2026-39970 TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload… Mitigation only Fix from $1,9502026-05-22 MEDIUM 5.4 CVE-2026-39964 TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble con… Patch available Fix from $1,6002026-05-22 HIGH 8.7 CVE-2026-28445 Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIc… Patch available Fix from $1,9502026-05-22 MEDIUM 6.1 CVE-2026-36226 Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decry… Mitigation only Fix from $1,6002026-05-22 MEDIUM 6.1 CVE-2026-42506 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in app… Net 0.55.0+ Fix from $1,6002026-05-22 MEDIUM 6.4 CVE-2026-9104 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due… Mitigation only Fix from $1,6002026-05-22 MEDIUM 6.1 CVE-2026-6864 The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, a… Mitigation only Fix from $1,6002026-05-22 MEDIUM 6.4 CVE-2026-7509 The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` att… Mitigation only Fix from $1,6002026-05-22 MEDIUM 6.1 CVE-2026-3481 The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and includin… Mitigation only Fix from $1,6002026-05-22 MEDIUM 5.4 CVE-2026-8139 Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-4093 In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templat… Taxonomy Term Reference Tree Widget 7.x-1.12+ Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-4929 Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affe… Simple Hierarchical Select after 7.x-1.10 Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-22678 Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status modu… Webmin 2.641+ Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-8203 Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privi… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48225 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject ar… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48226 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48227 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject … Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48228 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to injec… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48229 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48230 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that allows authenticated attackers … Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48218 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that allows authenticated attacker… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48219 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48220 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48221 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject … Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48222 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48223 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48224 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48214 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48215 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject a… Patch available Fix from $1,6002026-05-21