Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.1 CVE-2026-4344 A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Sto… Fusion 2702.1.47+ Fix from $1,9502026-04-14 HIGH 7.1 CVE-2026-4345 A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the… Fusion 2702.1.47+ Fix from $1,9502026-04-14 HIGH 7.1 CVE-2026-4369 A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigg… Fusion 2702.1.47+ Fix from $1,9502026-04-14 MEDIUM 6.1 CVE-2025-69993 Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied… Leaflet after 1.9.4 Fix from $1,6002026-04-14 MEDIUM 6.4 CVE-2026-4059 The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute… Mitigation only Fix from $1,6002026-04-14 MEDIUM 6.4 CVE-2026-1607 The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode i… Mitigation only Fix from $1,6002026-04-14 HIGH 7.2 CVE-2026-4388 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissi… Mitigation only Fix from $1,9502026-04-14 MEDIUM 5.4 CVE-2026-39426 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the fro… Maxkb 2.8.0+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-39423 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engin… Maxkb 2.8.0+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-39422 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability through the a… Maxkb 2.8.0+ Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-0512 Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attac… Mitigation only Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2025-70936 Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input … Mitigation only Fix from $1,6002026-04-13 HIGH 7.2 CVE-2026-40038 Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malici… Mitigation only Fix from $1,9502026-04-13 HIGH 8.7 CVE-2026-23891 Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the … Decidim 0.30.5 / 0.31.1+ Fix from $1,9502026-04-13 MEDIUM 5.4 CVE-2026-30812 Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects P… Pandora Fms 800.1+ Fix from $1,6002026-04-13 MEDIUM 5.4 CVE-2025-63743 Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker … Patch available Fix from $1,6002026-04-13 HIGH 8.0 CVE-2026-31281 Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users i… Mitigation only Fix from $1,9502026-04-13 MEDIUM 5.4 CVE-2026-35565 Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI … Storm 2.8.6+ Fix from $1,6002026-04-13 MEDIUM 5.4 CVE-2026-6179 Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser Nightwolf Penetration Testing Platform No fix yet Fix from $1,6002026-04-13 MEDIUM 6.1 CVE-2017-20239 MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through… Mdwiki No fix yet Fix from $1,6002026-04-12 MEDIUM 6.1 CVE-2026-1116 A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to versi… Lollms after 2.1.0 Fix from $1,6002026-04-12 CRITICAL 9.3 CVE-2026-31845 A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/… Mitigation only Fix from $2,3002026-04-11 MEDIUM 6.5 CVE-2026-23900 Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered. Maps after 6.0.2 Fix from $1,6002026-04-11 MEDIUM 6.1 CVE-2026-5226 The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and… Mitigation only Fix from $1,6002026-04-11 MEDIUM 6.4 CVE-2026-3498 The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and i… Mitigation only Fix from $1,6002026-04-11 MEDIUM 6.4 CVE-2026-4895 The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… Mitigation only Fix from $1,6002026-04-11 HIGH 7.2 CVE-2026-5217 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site S… Mitigation only Fix from $1,9502026-04-11 MEDIUM 5.4 CVE-2026-32893 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list … Chamilo Lms Patch available Fix from $1,6002026-04-10 MEDIUM 5.4 CVE-2026-35600 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdu… Vikunja 2.3.0+ Fix from $1,6002026-04-10 HIGH 7.1 CVE-2025-58920 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato cerato allows Reflected XSS.… Mitigation only Fix from $1,9502026-04-10