Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-48216 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to injec… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48217 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to i… Patch available Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-48213 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbi… Patch available Fix from $1,6002026-05-21 MEDIUM 6.1 CVE-2026-6841 Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft… Request Tracker 5.0.10 / 6.0.3+ Fix from $1,6002026-05-21 MEDIUM 6.4 CVE-2026-1543 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and inclu… Mitigation only Fix from $1,6002026-05-21 MEDIUM 5.4 CVE-2026-39960 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a text… Patch available Fix from $1,6002026-05-20 HIGH 7.6 CVE-2026-9144 Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface… Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.1 CVE-2026-47099 TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary Ja… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.8 CVE-2026-39311 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prio… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-26028 CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed du… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-30691 Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .… Mitigation only Fix from $1,6002026-05-20 HIGH 7.2 CVE-2026-7613 The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parame… Mitigation only Fix from $1,9502026-05-20 MEDIUM 5.4 CVE-2026-44924 InfoScale VIOM 9.1.3 allows XSS. Infoscale Operations Manager 9.1.3+ Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-4293 The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's brow… Mitigation only Fix from $1,6002026-05-20 HIGH 7.6 CVE-2026-5783 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Tra… Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-24573 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This i… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.4 CVE-2026-2955 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in ve… Mitigation only Fix from $1,6002026-05-20 HIGH 7.4 CVE-2026-7460 mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entr… Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.1 CVE-2026-8624 The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, a… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-8626 The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-8627 The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and i… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-7462 The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and includin… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.4 CVE-2026-8038 The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shor… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.4 CVE-2026-6549 The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.4 CVE-2026-5293 The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in … Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.4 CVE-2026-6397 The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up … Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-6365 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.5.9 / 10.6.7+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-6367 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 11.3.7+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-6871 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (X… Obfuscate 2.0.2+ Fix from $1,6002026-05-19 MEDIUM 5.4 CVE-2026-8493 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Script… Colorbox Inline 2.1.1+ Fix from $1,6002026-05-19