Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-6236 The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in all versions up to, and includi… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-6246 The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the … Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4279 The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versio… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4353 The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in al… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-5748 The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and includ… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-5767 The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up … Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-5820 The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and inclu… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4125 The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and includ… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4076 The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attribute… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4082 The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4085 The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the '… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4088 The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and incl… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4089 The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and i… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.4 CVE-2026-4074 The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in al… Mitigation only Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-1845 The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 … Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2026-40451 DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute ar… Mitigation only Fix from $1,6002026-04-22 MEDIUM 5.4 CVE-2026-41061 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-41063 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides … Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-40927 Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a … Docmost 0.80.0+ Fix from $1,6002026-04-21 HIGH 7.0 CVE-2026-40875 mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful con… Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.3 CVE-2026-40872 mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs r… Mitigation only Fix from $2,3002026-04-21 HIGH 8.9 CVE-2026-40873 mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects atta… Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.1 CVE-2026-41456 Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers… Patch available Fix from $1,6002026-04-21 HIGH 8.5 CVE-2026-40568 FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the… Patch available Fix from $1,9502026-04-21 MEDIUM 5.7 CVE-2026-35451 Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a l… Patch available Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-40565 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php convert… Freescout 1.8.213+ Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2025-41011 HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack o… Php Point Of Sale Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.1 CVE-2026-31013 Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Depart… Ad Phonebook 4.0.1.1+ Fix from $1,6002026-04-21 MEDIUM 5.1 CVE-2025-10354 Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the vic… Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-6779 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21