Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-6711 The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and includin… Mitigation only Fix from $1,6002026-04-21 HIGH 8.1 CVE-2026-40497 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`… Freescout 1.8.213+ Fix from $1,9502026-04-21 MEDIUM 6.4 CVE-2026-4852 The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Sour… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-39112 Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visi… Mitigation only Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-23756 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not … Helpdesk 4.99.9+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-23757 GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly t… Helpdesk 4.99.10+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-23758 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members t… Helpdesk 4.99.9+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-34429 Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions … Patch available Fix from $1,6002026-04-20 MEDIUM 6.1 CVE-2026-32963 SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affect… Sd 330ac Firmware 1.50 / 5.1.0+ Fix from $1,6002026-04-20 MEDIUM 6.4 CVE-2026-0868 The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly short… Mitigation only Fix from $1,6002026-04-19 MEDIUM 6.4 CVE-2026-2986 The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to… Mitigation only Fix from $1,6002026-04-18 MEDIUM 6.4 CVE-2026-0894 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in… Mitigation only Fix from $1,6002026-04-18 MEDIUM 5.4 CVE-2026-2505 The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_… Mitigation only Fix from $1,6002026-04-18 MEDIUM 6.4 CVE-2026-6048 The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attribu… Mitigation only Fix from $1,6002026-04-18 MEDIUM 6.4 CVE-2026-4801 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all ver… Mitigation only Fix from $1,6002026-04-18 MEDIUM 6.4 CVE-2026-1559 The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and includi… Mitigation only Fix from $1,6002026-04-18 MEDIUM 6.1 CVE-2026-1838 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including… Mitigation only Fix from $1,6002026-04-18 CRITICAL 9.0 CVE-2026-40487 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr… Postiz 2.21.6+ Fix from $2,3002026-04-18 MEDIUM 5.4 CVE-2026-40483 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTM… Patch available Fix from $1,6002026-04-18 MEDIUM 6.4 CVE-2026-2434 The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and … Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.4 CVE-2026-40479 Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape … Kimai 2.53.0+ Fix from $1,6002026-04-17 MEDIUM 5.4 CVE-2026-40353 wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs … Wger 2.5+ Fix from $1,6002026-04-17 MEDIUM 6.4 CVE-2026-40282 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti… No fix yet Fix from $1,6002026-04-17 MEDIUM 6.8 CVE-2026-40284 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti… Mitigation only Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-40286 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in … Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.1 CVE-2026-40302 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template … Zrok 2.0.1+ Fix from $1,6002026-04-17 MEDIUM 6.1 CVE-2026-33436 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints … Stirling Pdf 2.0.0+ Fix from $1,6002026-04-17 HIGH 7.6 CVE-2026-40283 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenti… Wegia 3.6.10+ Fix from $1,9502026-04-17 MEDIUM 6.4 CVE-2026-5162 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_te… Mitigation only Fix from $1,6002026-04-17 HIGH 7.2 CVE-2026-5231 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includi… Mitigation only Fix from $1,9502026-04-17