Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.7 CVE-2026-31205 Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanit… Mitigation only Fix from $1,6002026-05-04 CRITICAL 9.8 CVE-2025-14320 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Tra… Mitigation only Fix from $2,3002026-05-04 MEDIUM 6.1 CVE-2026-7371 Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A… Gv Lpc2011 Firmware Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.1 CVE-2026-42366 Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A… Gv Lpc2011 Firmware Mitigation only Fix from $1,6002026-05-04 HIGH 7.2 CVE-2026-5063 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in… Mitigation only Fix from $1,9502026-05-03 MEDIUM 6.4 CVE-2026-0703 The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current… Mitigation only Fix from $1,6002026-05-02 MEDIUM 5.8 CVE-2026-6817 The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and in… Mitigation only Fix from $1,6002026-05-02 MEDIUM 5.4 CVE-2026-4790 The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… Mitigation only Fix from $1,6002026-05-02 MEDIUM 5.4 CVE-2026-5077 The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficien… Mitigation only Fix from $1,6002026-05-02 HIGH 7.2 CVE-2026-5324 The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2.8.… Mitigation only Fix from $1,9502026-05-02 HIGH 7.2 CVE-2026-5113 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2… No fix yet Fix from $1,9502026-05-02 MEDIUM 6.4 CVE-2026-6916 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site … Mitigation only Fix from $1,6002026-05-02 HIGH 7.2 CVE-2026-5109 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficie… Mitigation only Fix from $1,9502026-05-02 HIGH 7.2 CVE-2026-5110 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is d… Mitigation only Fix from $1,9502026-05-02 HIGH 7.2 CVE-2026-5111 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficie… Mitigation only Fix from $1,9502026-05-02 HIGH 7.2 CVE-2026-5112 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is d… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.4 CVE-2026-4658 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.4 CVE-2026-7209 The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versi… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.4 CVE-2026-6378 The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in… Patch available Fix from $1,6002026-05-02 MEDIUM 6.1 CVE-2025-69606 Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/erro… Mitigation only Fix from $1,6002026-05-01 MEDIUM 5.4 CVE-2026-40201 @diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file. Patch available Fix from $1,6002026-05-01 MEDIUM 6.4 CVE-2026-6127 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to,… No fix yet Fix from $1,6002026-05-01 MEDIUM 6.1 CVE-2024-13362 Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insuff… Mitigation only Fix from $1,6002026-05-01 MEDIUM 6.1 CVE-2026-36761 A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scr… Mitigation only Fix from $1,6002026-04-30 MEDIUM 6.1 CVE-2026-36763 A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arb… Mitigation only Fix from $1,6002026-04-30 MEDIUM 5.4 CVE-2026-36766 Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to ex… Mitigation only Fix from $1,6002026-04-30 MEDIUM 6.1 CVE-2026-38939 Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive informa… Mitigation only Fix from $1,6002026-04-30 MEDIUM 6.1 CVE-2026-38940 Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php com… Mitigation only Fix from $1,6002026-04-30 MEDIUM 5.4 CVE-2026-1493 LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, all… Lex Baza Dokumentow 1.3.4+ Fix from $1,6002026-04-30 MEDIUM 6.1 CVE-2018-25309 MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threa… Recent Threads On Index No fix yet Fix from $1,6002026-04-29