Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.4 CVE-2026-4005 The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up t… Mitigation only Fix from $1,6002026-04-15 MEDIUM 6.4 CVE-2026-4011 The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions … Mitigation only Fix from $1,6002026-04-15 HIGH 7.2 CVE-2026-3643 The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The pl… Mitigation only Fix from $1,9502026-04-15 HIGH 8.9 CVE-2025-40899 A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An… Mitigation only Fix from $1,9502026-04-15 MEDIUM 6.1 CVE-2026-5160 Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of… Goldmark 1.7.17+ Fix from $1,6002026-04-15 MEDIUM 5.4 CVE-2026-26291 Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed… Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.4 CVE-2026-40096 immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the s… Immich 2.7.3+ Fix from $1,6002026-04-15 HIGH 7.2 CVE-2026-2834 The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description… Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.4 CVE-2026-34212 Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docm… Docmost 0.71.0+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-34161 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists i… Chamilo Lms after 1.11.38 Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-34624 Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could … Experience Manager 6.5.11.8+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-34625 Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could … Experience Manager 6.5.11.8+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-34623 Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could … Experience Manager 6.5.11.8+ Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-34614 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to conv… Connect 12.11 / 2025.9.15+ Fix from $1,6002026-04-14 HIGH 8.7 CVE-2026-34617 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation… Connect 12.11 / 2025.9.15+ Fix from $1,9502026-04-14 MEDIUM 6.1 CVE-2026-32196 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo… Windows Admin Center 2511+ Fix from $1,6002026-04-14 CRITICAL 9.3 CVE-2026-27246 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 MEDIUM 5.4 CVE-2026-27288 Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could … Experience Manager 6.5.11.8+ Fix from $1,6002026-04-14 CRITICAL 9.3 CVE-2026-27243 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-27245 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 MEDIUM 5.4 CVE-2026-24906 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulner… October after 4.1.9 Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-24907 October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulner… October after 4.1.9 Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-20945EPSS 25% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20210+ Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-21331 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to conv… Connect 12.11 / 2025.9.15+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-22154 An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3,… Fortisoar 7.5.3 / 7.6.4+ Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2025-65134 In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2025-65136 In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter. Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2025-65132 alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject a… Mitigation only Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2025-61886 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox… Fortisandbox 5.0.5+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-4914 Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User… Mitigation only Fix from $1,6002026-04-14