Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-6095 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS… Orejime 2.0.16+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-5090 Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quo… Patch available Fix from $1,6002026-05-19 HIGH 8.7 CVE-2026-34241 CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability i… Mitigation only Fix from $1,9502026-05-19 HIGH 8.6 CVE-2026-34463 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue or… Patch available Fix from $1,9502026-05-19 MEDIUM 6.8 CVE-2026-33741 EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments … Mitigation only Fix from $1,6002026-05-19 CRITICAL 9.1 CVE-2026-8948 Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $2,3002026-05-19 MEDIUM 5.4 CVE-2025-40904 A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenti… Cmc 26.1.0+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31906 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-27737 BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user'… Patch available Fix from $1,6002026-05-18 MEDIUM 6.1 CVE-2026-45231 DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber… Patch available Fix from $1,6002026-05-18 MEDIUM 6.1 CVE-2026-45494 Microsoft Edge (Chromium-based) Spoofing Vulnerability Edge Chromium 148.0.3967.70+ Fix from $1,6002026-05-18 MEDIUM 6.1 CVE-2026-29964 HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-co… Mailinspector Mitigation only Fix from $1,6002026-05-18 MEDIUM 6.1 CVE-2026-29965 HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of us… Mailinspector Mitigation only Fix from $1,6002026-05-18 HIGH 8.8 CVE-2026-7498 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and O… Mitigation only Fix from $1,9502026-05-18 HIGH 8.8 CVE-2026-3220 The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vuln… Mitigation only Fix from $1,9502026-05-18 HIGH 7.1 CVE-2026-6495 The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec… Mitigation only Fix from $1,9502026-05-18 MEDIUM 6.1 CVE-2018-25331 Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by ma… No fix yet Fix from $1,6002026-05-17 MEDIUM 5.4 CVE-2021-47981 Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by su… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2021-47957 Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitti… No fix yet Fix from $1,6002026-05-16 HIGH 7.2 CVE-2021-47975 WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through… No fix yet Fix from $1,9502026-05-16 MEDIUM 5.3 CVE-2021-47934 MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post c… No fix yet Fix from $1,6002026-05-16 MEDIUM 5.4 CVE-2021-47955 CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicio… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2020-37240 Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scrip… No fix yet Fix from $1,6002026-05-16 HIGH 7.5 CVE-2020-37245 Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside … No fix yet Fix from $1,9502026-05-16 MEDIUM 6.4 CVE-2020-37233 WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privile… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2020-37235 WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject mal… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2020-37236 NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scrip… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2020-37237 Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts thr… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.4 CVE-2020-37238 CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject mal… No fix yet Fix from $1,6002026-05-16