Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-8656 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitizat… Patch available Fix from $1,6002026-05-16 HIGH 8.1 CVE-2026-45665 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS… Open Webui 0.8.0+ Fix from $1,9502026-05-15 HIGH 8.7 CVE-2026-45315 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload end… Open Webui 0.9.3+ Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-45318 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, his advisory tracks a regression o… Open Webui 0.9.3+ Fix from $1,6002026-05-15 MEDIUM 5.4 CVE-2026-45299 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the… Open Webui 0.8.0+ Fix from $1,6002026-05-15 HIGH 7.7 CVE-2026-45303 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, s… Open Webui 0.6.5+ Fix from $1,9502026-05-15 HIGH 8.7 CVE-2026-44549 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are preview… Open Webui 0.8.0+ Fix from $1,9502026-05-15 HIGH 7.3 CVE-2026-44721 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a stored cross-site scripting (XSS… Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 7.6 CVE-2026-46367 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript … Mitigation only Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-46360 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding… Mitigation only Fix from $1,6002026-05-15 MEDIUM 6.9 CVE-2026-46361 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.4 CVE-2026-46363 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through enco… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.3 CVE-2026-45622 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.1 CVE-2026-45616 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixe… No fix yet Fix from $1,6002026-05-15 MEDIUM 6.1 CVE-2026-44366 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripti… Mitigation only Fix from $1,6002026-05-15 MEDIUM 6.1 CVE-2021-47967 PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by mani… No fix yet Fix from $1,6002026-05-15 MEDIUM 6.4 CVE-2021-47968 Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malicious scripts by submitting un… No fix yet Fix from $1,6002026-05-15 MEDIUM 6.4 CVE-2021-47962 Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to in… No fix yet Fix from $1,6002026-05-15 HIGH 7.2 CVE-2021-47963 Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads in… No fix yet Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-23695 Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display t… Patch available Fix from $1,6002026-05-15 MEDIUM 6.4 CVE-2026-6415 The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. Thi… Mitigation only Fix from $1,6002026-05-15 MEDIUM 6.4 CVE-2026-6646 The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including,… Mitigation only Fix from $1,6002026-05-15 MEDIUM 5.4 CVE-2026-24662 Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing ma… Mitigation only Fix from $1,6002026-05-15 CRITICAL 9.3 CVE-2026-44212 PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the … Mitigation only Fix from $2,3002026-05-14 MEDIUM 5.4 CVE-2026-44429 The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served a… Mcp Registry 1.7.7+ Fix from $1,6002026-05-14 CRITICAL 9.0 CVE-2026-45375 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version f… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.4 CVE-2026-44670 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTM… Mitigation only Fix from $2,3002026-05-14 HIGH 8.3 CVE-2026-44586 SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metada… Mitigation only Fix from $1,9502026-05-14 CRITICAL 9.4 CVE-2026-44588 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-l… Mitigation only Fix from $2,3002026-05-14 MEDIUM 6.1 CVE-2026-42897 KEVEPSS 70% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to … Exchange Server 15.02.2562.043+ Fix from $1,6002026-05-14