Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-6237 The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions u… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.4 CVE-2026-6247 The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortco… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.4 CVE-2026-6256 The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all ve… Mitigation only Fix from $1,6002026-05-12 HIGH 7.2 CVE-2026-6690 The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all version… Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.4 CVE-2026-4859 The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortc… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.4 CVE-2026-4920 The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and incl… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.4 CVE-2026-5340 The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.4 CVE-2026-2300 The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and incl… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.1 CVE-2026-40137 SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.1 CVE-2026-27682 Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a… Netweaver Application Server Abap Mitigation only Fix from $1,6002026-05-12 HIGH 8.7 CVE-2026-45392 DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an auth… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.3 CVE-2026-43900 DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Script… Mitigation only Fix from $2,3002026-05-11 MEDIUM 6.1 CVE-2026-42554 Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitr… Fiber 2.52.12 / 3.1.0+ Fix from $1,6002026-05-11 HIGH 7.3 CVE-2026-43887 Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other us… Mitigation only Fix from $1,9502026-05-11 MEDIUM 6.1 CVE-2026-43878 WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the attacker-controlled user and pa… Patch available Fix from $1,6002026-05-11 MEDIUM 6.4 CVE-2026-43876 WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST par… Patch available Fix from $1,6002026-05-11 MEDIUM 6.8 CVE-2026-45026 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authentic… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.8 CVE-2026-45025 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authentic… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.4 CVE-2026-42870 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the follow… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2026-42872 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.1 CVE-2026-7308 An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of a… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-42857 Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion… Openedx 2026-04-24+ Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-38569 HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.7 CVE-2026-41250 Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is… Patch available Fix from $1,6002026-05-11 MEDIUM 6.2 CVE-2026-44737 grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modif… Patch available Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-42842 The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Gr… Patch available Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2026-36906 Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function Mitigation only Fix from $1,6002026-05-11 HIGH 8.9 CVE-2026-42611 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection … Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 5.4 CVE-2026-42612 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level ac… Grav after 1.8.0 Fix from $1,6002026-05-11 MEDIUM 5.1 CVE-2026-3320 Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in th… Mitigation only Fix from $1,6002026-05-11