Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-4364 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,6002026-04-01 CRITICAL 9.0 CVE-2026-34529 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver… Filebrowser 2.62.2+ Fix from $2,3002026-04-01 MEDIUM 6.9 CVE-2026-34530 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver… Filebrowser 2.62.2+ Fix from $1,6002026-04-01 HIGH 8.7 CVE-2026-34748 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS… Payload 3.78.0+ Fix from $1,9502026-04-01 MEDIUM 6.1 CVE-2026-33978 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share … Notesnook Mobile 3.3.17+ Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-20085 A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack … Mitigation only Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-30526 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login p… Zoo Management System No fix yet Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-29598 Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers … Mitigation only Fix from $1,6002026-04-01 MEDIUM 6.4 CVE-2025-13535 The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in al… Mitigation only Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-3877 A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a ma… Fm 10.13.403+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-21631 Lack of output escaping leads to a XSS vector in the multilingual associations component. Joomla\! 5.4.4 / 6.0.4+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-21632 Lack of output escaping for article titles leads to XSS vectors in various locations. Joomla\! 5.4.4 / 6.0.4+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-34889 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery P… Mitigation only Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-5255 A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component … Simple Laundry System No fix yet Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-35054 XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts throug… Xenforo 2.3.9+ Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-35055 XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicio… Xenforo 2.2.18 / 2.3.9+ Fix from $1,6002026-04-01 MEDIUM 5.4 CVE-2026-35057 XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy pr… Xenforo 2.2.19 / 2.3.10+ Fix from $1,6002026-04-01 MEDIUM 6.4 CVE-2026-2480 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the… Mitigation only Fix from $1,6002026-03-31 HIGH 8.2 CVE-2026-34585 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side… Siyuan 3.6.2+ Fix from $1,9502026-03-31 MEDIUM 6.1 CVE-2026-34605 SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to… Siyuan 3.6.2+ Fix from $1,6002026-03-31 CRITICAL 9.0 CVE-2026-34448 SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field … Siyuan 3.6.2+ Fix from $2,3002026-03-31 MEDIUM 6.1 CVE-2026-34405 Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old… Og Image 6.2.5+ Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-34739 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request paramete… Avideo after 26.0 Fix from $1,6002026-03-31 MEDIUM 6.4 CVE-2026-34716 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifica… Avideo after 26.0 Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-34396 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms wi… Avideo after 26.0 Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-34206 Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet.… Captcha Protect 1.12.2+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-32607 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-32243 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-32273 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 6.1 CVE-2026-34231 Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} templat… Slippers after 0.6.2 Fix from $1,6002026-03-31