Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-41067 Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/scr… Astro 6.1.6+ Fix from $1,6002026-04-24 MEDIUM 6.1 CVE-2025-61872 Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the … Mitigation only Fix from $1,6002026-04-24 MEDIUM 6.5 CVE-2026-41043 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate… Activemq 5.19.6 / 6.2.5+ Fix from $1,6002026-04-24 MEDIUM 6.4 CVE-2026-4078 The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-… Mitigation only Fix from $1,6002026-04-24 MEDIUM 6.4 CVE-2026-5428 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel wid… Mitigation only Fix from $1,6002026-04-24 MEDIUM 6.1 CVE-2026-41430 Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect para… Press 0.16.0+ Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-41318 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, … Anythingllm 1.12.1+ Fix from $1,6002026-04-24 MEDIUM 6.1 CVE-2026-41305 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior t… Mitigation only Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-31953 Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripti… Xibo 4.4.1+ Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-41241 pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display nam… Pretalx 2026.1.0+ Fix from $1,6002026-04-23 MEDIUM 6.9 CVE-2026-41238 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollutio… Mitigation only Fix from $1,6002026-04-23 MEDIUM 6.8 CVE-2026-41239 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TE… Mitigation only Fix from $1,6002026-04-23 MEDIUM 6.1 CVE-2026-41240 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS a… Dompurify 3.4.0+ Fix from $1,6002026-04-23 CRITICAL 9.9 CVE-2026-40470 A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the docum… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.9 CVE-2026-40472 In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cro… Mitigation only Fix from $2,3002026-04-23 MEDIUM 6.5 CVE-2025-62110 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored X… Mitigation only Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-28040 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCom… Mitigation only Fix from $1,6002026-04-23 MEDIUM 6.4 CVE-2026-3361 The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and … Mitigation only Fix from $1,6002026-04-23 MEDIUM 5.4 CVE-2026-3007 Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user ac… Mitigation only Fix from $1,6002026-04-23 MEDIUM 5.4 CVE-2026-2951 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … Mitigation only Fix from $1,6002026-04-23 HIGH 8.5 CVE-2026-41200 STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.… Mitigation only Fix from $1,9502026-04-23 MEDIUM 6.4 CVE-2026-1923 The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up… Mitigation only Fix from $1,6002026-04-23 MEDIUM 5.4 CVE-2026-3837 An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the aff… Frappe Patch available Fix from $1,6002026-04-22 MEDIUM 5.4 CVE-2026-3673 An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where… Frappe No fix yet Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2026-5262 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that … GitLab 18.9.6 / 18.10.4+ Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2026-30139 A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to … Patch available Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2024-58344 Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript c… No fix yet Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2018-25269 ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embe… Icewarp No fix yet Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-1395 The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id attribute in all versions up to… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-1913 The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_link shortcode in all versions … Mitigation only Fix from $1,6002026-04-22