Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-7475 The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to,… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.4 CVE-2026-7650 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-down… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.4 CVE-2026-5341 The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all ve… Mitigation only Fix from $1,6002026-05-08 HIGH 7.2 CVE-2026-7330 The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to ins… Mitigation only Fix from $1,9502026-05-08 MEDIUM 5.4 CVE-2024-33724 SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.1 CVE-2023-42343 A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.1 CVE-2023-42345 A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.1 CVE-2022-23961 In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthen… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.1 CVE-2026-8106 A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential the… Enterprise Server 3.19.6 / 3.20.2+ Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2026-41929 Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attac… Patch available Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2026-32207 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per… Azure Machine Learning Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were t… Go 1.25.10 / 1.26.3+ Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2026-44742 Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2… Postorius after 1.3.13 Fix from $1,6002026-05-07 HIGH 7.6 CVE-2026-41904 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission c… Mitigation only Fix from $1,9502026-05-07 HIGH 7.0 CVE-2026-41653 BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. … Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2026-36388 A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This f… Mitigation only Fix from $1,6002026-05-07 MEDIUM 5.4 CVE-2026-36341 Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment fie… Patch available Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2025-67202 Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL be… Mitigation only Fix from $1,6002026-05-07 HIGH 7.1 CVE-2026-41554 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issu… Mitigation only Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-5784 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD… Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2026-8080 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue… Misp 2.5.37+ Fix from $1,6002026-05-07 HIGH 8.8 CVE-2026-3953 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Pro… Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.5 CVE-2026-27421 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XS… Mitigation only Fix from $1,6002026-05-07 MEDIUM 5.9 CVE-2025-62127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.1 CVE-2026-41661 Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admid… Mitigation only Fix from $1,6002026-05-07 CRITICAL 9.1 CVE-2026-41201 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In vers… Mitigation only Fix from $2,3002026-05-07 MEDIUM 5.4 CVE-2026-40296 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatt… Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,6002026-05-06 HIGH 8.4 CVE-2026-40171 In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @… Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.4 CVE-2026-8012 Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to i… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06 MEDIUM 5.4 CVE-2026-7958 Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06