Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-7939 Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (U… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06 MEDIUM 5.4 CVE-2026-36358 Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner … Mitigation only Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2025-59854 HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection … Dfxanalytics 4.1+ Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2025-31970 HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict dire… Dfxanalytics 4.1+ Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2026-42509 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke… Wicket 10.9.0+ Fix from $1,6002026-05-06 HIGH 7.2 CVE-2026-7332 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookin… Mitigation only Fix from $1,9502026-05-06 MEDIUM 6.4 CVE-2026-7457 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficien… Mitigation only Fix from $1,6002026-05-06 HIGH 7.3 CVE-2026-23928 The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This … Mitigation only Fix from $1,9502026-05-06 MEDIUM 6.4 CVE-2026-6672 The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all ve… Mitigation only Fix from $1,6002026-05-06 HIGH 7.3 CVE-2026-23926 An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip … Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.4 CVE-2026-35453 PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3… Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2026-38947 FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. No fix yet Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2026-38432 ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit … Erpnext after 15.103.1 Fix from $1,6002026-05-05 MEDIUM 5.4 CVE-2026-27694 Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates ins… Traccar 6.13.0+ Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2023-54349 AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitt… No fix yet Fix from $1,6002026-05-05 HIGH 7.2 CVE-2026-4803 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action… Mitigation only Fix from $1,9502026-05-05 MEDIUM 6.4 CVE-2026-5159 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_te… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.4 CVE-2026-4665 The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2026-6704 The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including,… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.4 CVE-2026-5505 The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and includ… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.4 CVE-2026-6255 The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode i… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.1 CVE-2026-6696 The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_name', 'last_name', and 'phone… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.4 CVE-2026-2868 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separato… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.4 CVE-2026-4730 The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerable to Stored Cross-Site Script… Mitigation only Fix from $1,6002026-05-05 MEDIUM 5.5 CVE-2026-5247 The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of t… Mitigation only Fix from $1,6002026-05-05 CRITICAL 9.6 CVE-2026-42235 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a mali… N8n 1.123.32 / 2.17.4+ Fix from $2,3002026-05-04 MEDIUM 6.1 CVE-2026-42138 Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can u… Dify 1.13.1+ Fix from $1,6002026-05-04 MEDIUM 6.0 CVE-2026-42052 Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for … Mitigation only Fix from $1,6002026-05-04 CRITICAL 9.6 CVE-2026-42090 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi… Notesnook Desktop 3.3.15 / 3.3.20+ Fix from $2,3002026-05-04 MEDIUM 6.1 CVE-2026-38669 wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog. Mitigation only Fix from $1,6002026-05-04