Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.9
CVE-2026-39838
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage …
Mitigation only
MEDIUM 6.1
CVE-2026-39840
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extensio…
Cargo
3.8.7+
MEDIUM 5.4
CVE-2026-39380
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc…
Open Source Point Of Sale
3.4.3+
MEDIUM 5.4
CVE-2026-39367
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-contro…
Avideo
after 26.0
HIGH 8.1
CVE-2026-39344
ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page…
Churchcrm
7.1.0+
MEDIUM 6.1
CVE-2026-39335
ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. Th…
Churchcrm
after 7.1.1
MEDIUM 6.1
CVE-2026-39336
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields s…
Churchcrm
7.1.0+
MEDIUM 6.1
CVE-2026-39338
ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search param…
Churchcrm
after 7.0.5
HIGH 8.9
CVE-2026-39328
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profil…
Churchcrm
7.1.0+
HIGH 8.7
CVE-2026-39332
ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any …
Churchcrm
7.1.0+
HIGH 8.7
CVE-2026-39333
ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and Date…
Churchcrm
7.1.0+
HIGH 8.0
CVE-2026-35575
ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s g…
Churchcrm
6.5.3+
HIGH 8.7
CVE-2026-35576
ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within th…
Churchcrm
7.0.0+
MEDIUM 6.1
CVE-2026-35608
QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application…
Quickdrop
1.5.3+
HIGH 8.7
CVE-2026-35574
ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor al…
Churchcrm
6.5.3+
HIGH 7.6
CVE-2026-35534
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to inc…
Churchcrm
7.1.0+
MEDIUM 5.4
CVE-2026-35460
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name dir…
Papra
26.4.0+
MEDIUM 5.4
CVE-2026-3466
Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and …
Checkmk
Mitigation only
MEDIUM 5.4
CVE-2026-33865
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authentic…
Mlflow
after 3.10.1
MEDIUM 5.4
CVE-2026-4420
Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges…
Bludit
Mitigation only
MEDIUM 6.1
CVE-2026-22675
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute…
Ocs Inventory Server
after 2.12.3
MEDIUM 6.1
CVE-2026-35399
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through…
Wegia
3.6.9+
MEDIUM 5.4
CVE-2026-35208
lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage…
Lila
2026-03-31+
MEDIUM 5.4
CVE-2026-35390
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Poli…
Webmail
1.4.11+
MEDIUM 5.4
CVE-2026-35166
Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escap…
Hugo
0.159.2+
MEDIUM 5.4
CVE-2026-35046
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authentic…
Recipes
2.6.4+
CRITICAL 9.8
CVE-2026-35052
D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p…
D Tale
3.22.0+
CRITICAL 9.0
CVE-2026-34989
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.0.0+
CRITICAL 9.0
CVE-2026-35035
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…
Ci4ms
0.31.2.0+
MEDIUM 5.4
CVE-2026-31313
An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbit…
Feehi Cms
No fix yet