Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-39508 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce … Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-39482 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allo… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-39483 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit … Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-1396 The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in … Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4655 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to an… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-5506 The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-5508 The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in all versions up to, and inclu… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4871 The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' attributes of the `scm_memb… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3618 The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [print_clmns] sh… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3142 The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_var' parameter … Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2025-1794 The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-27787 Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on… Matcha Sns after 1.3.9 Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3311 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Store… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4333 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_c… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4341 The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mou… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4785 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3239 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3513 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode i… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-3600 The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-year… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-4379 The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in a… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2026-2988 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.1 CVE-2026-32289 Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches w… Go 1.25.9 / 1.26.2+ Fix from $1,6002026-04-08 MEDIUM 6.1 CVE-2026-4394 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.9 CVE-2026-39935 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEv… Mitigation only Fix from $1,6002026-04-07 MEDIUM 6.9 CVE-2026-39936 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Exte… Mitigation only Fix from $1,6002026-04-07 CRITICAL 9.0 CVE-2026-39846 SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si… Siyuan 3.6.4+ Fix from $2,3002026-04-07 MEDIUM 6.9 CVE-2026-39933 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatc… Mitigation only Fix from $1,6002026-04-07 MEDIUM 6.1 CVE-2026-39400 Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_ev… Cronicle 0.9.111+ Fix from $1,6002026-04-07 MEDIUM 5.4 CVE-2026-32712 Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc… Open Source Point Of Sale 3.4.3+ Fix from $1,6002026-04-07 MEDIUM 6.1 CVE-2026-39841 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allow… Cargo 3.8.7+ Fix from $1,6002026-04-07