Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.1 CVE-2026-3319 Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in th… Mitigation only Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-34089 Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2. Scribunto 1.45.2+ Fix from $1,9502026-05-11 MEDIUM 6.1 CVE-2025-65417 docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application. Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2025-61308 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2025-61309 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2025-61310 A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a… Mitigation only Fix from $1,6002026-05-11 HIGH 7.3 CVE-2025-61311 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c all… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2025-61312 A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c al… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2025-61313 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.1… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2025-61314 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a… Mitigation only Fix from $1,9502026-05-11 MEDIUM 6.1 CVE-2025-61305 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c a… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2025-61306 A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2025-61307 A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c all… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.1 CVE-2026-6909 ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.1 CVE-2026-6956 ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.1 CVE-2022-50963 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_fro… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50964 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50965 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and creat… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50966 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and create… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50967 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and cre… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50968 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and cr… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50969 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_… No fix yet Fix from $1,6002026-05-10 MEDIUM 5.4 CVE-2022-50970 WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50957 Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject maliciou… Avatar Uploader No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50958 WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50959 WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject maliciou… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50960 WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter … No fix yet Fix from $1,6002026-05-10 MEDIUM 6.4 CVE-2022-50961 WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject ar… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2022-50962 uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and cr… No fix yet Fix from $1,6002026-05-10 MEDIUM 6.4 CVE-2022-50945 WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal… No fix yet Fix from $1,6002026-05-10