Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-40212 OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is us… Mitigation only Fix from $1,6002026-04-10 CRITICAL 9.6 CVE-2026-1115 A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.… Lollms after 2.1.0 Fix from $2,3002026-04-10 MEDIUM 6.4 CVE-2026-2305 The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `a… Mitigation only Fix from $1,6002026-04-10 MEDIUM 6.1 CVE-2026-4305 The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' param… Mitigation only Fix from $1,6002026-04-10 MEDIUM 6.4 CVE-2026-1263 The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input s… Mitigation only Fix from $1,6002026-04-10 MEDIUM 6.1 CVE-2026-40112 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effect… Praisonai 4.5.128+ Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2026-21904 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attac… Junos Space Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54364 Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by ma… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54360 Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating th… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54361 Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manip… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54362 Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by m… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54363 Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by m… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2023-54358 WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious… No fix yet Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2025-63238 A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInst… Limesurvey 6.15.12+ Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2025-70797 Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] … Limesurvey Patch available Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2026-39941 ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and ED… Churchcrm 7.1.0+ Fix from $1,6002026-04-09 MEDIUM 5.4 CVE-2025-70365 A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2025-45806 A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrary web scripts or HTML via a c… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.4 CVE-2026-3005 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to,… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.4 CVE-2026-5742 The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient inp… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.4 CVE-2026-4336 The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.4 CVE-2026-4429 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attri… Mitigation only Fix from $1,6002026-04-09 MEDIUM 6.4 CVE-2026-5357 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in ver… Mitigation only Fix from $1,6002026-04-09 MEDIUM 5.1 CVE-2026-3438 A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote a… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-4332 GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in cus… GitLab 18.8.9 / 18.9.5+ Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-5711 The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider b… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-40028 Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allows an attacker to execute arbi… Hayabusa 3.8.0+ Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-5451 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions … No fix yet Fix from $1,6002026-04-08 MEDIUM 6.1 CVE-2026-39416 AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) … Ail Framework after 6.7 Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-35455 immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama… Immich 2.7.0+ Fix from $1,6002026-04-08