Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-33738
Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and re…
Lychee
7.5.3+
MEDIUM 5.4
CVE-2026-33742
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 a…
Invoice Ninja
5.13.4+
MEDIUM 6.1
CVE-2026-3528
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scr…
Calculation Fields
1.0.4+
MEDIUM 5.4
CVE-2026-33628
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja…
Invoice Ninja
5.13.4+
MEDIUM 6.1
CVE-2026-33525
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via …
Authelia
No fix yet
MEDIUM 6.1
CVE-2026-29969
A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Jav…
Staffwiki
No fix yet
MEDIUM 6.1
CVE-2026-34071
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version 2.7.3, the /api/v1/convert/em…
Stirling Pdf
No fix yet
MEDIUM 6.1
CVE-2026-33402
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contai…
Sakai
23.5 / 25.2+
MEDIUM 6.1
CVE-2026-29934
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript …
Lightcms
No fix yet
MEDIUM 6.1
CVE-2026-30162
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
Timo
No fix yet
MEDIUM 6.1
CVE-2026-29933
A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascri…
Yzmcms
No fix yet
HIGH 8.7
CVE-2026-28297
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…
Observability Self Hosted
2026.1.1+
HIGH 8.1
CVE-2026-28298
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…
Observability Self Hosted
2026.1.1+
HIGH 7.2
CVE-2026-2231
The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.…
Mitigation only
MEDIUM 6.1
CVE-2025-41027
Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br…
Gdtaller
Mitigation only
MEDIUM 6.1
CVE-2025-41026
Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br…
Gdtaller
Mitigation only
MEDIUM 6.1
CVE-2018-25210
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to m…
E Ticaret
after 4.0.0
MEDIUM 6.1
CVE-2026-4849
A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component …
Simple Laundry System
No fix yet
HIGH 7.2
CVE-2026-4329
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and…
Mitigation only
MEDIUM 6.4
CVE-2026-4389
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` …
Mitigation only
MEDIUM 6.4
CVE-2026-4278
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and…
Mitigation only
MEDIUM 6.4
CVE-2026-4075
The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up t…
Mitigation only
MEDIUM 5.4
CVE-2026-4335
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to,…
Mitigation only
MEDIUM 6.1
CVE-2026-1986
The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t…
Mitigation only
MEDIUM 6.1
CVE-2026-33933
OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to ver…
Openemr
8.0.0.3+
MEDIUM 5.4
CVE-2026-33932
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-sit…
Openemr
8.0.0.3+
MEDIUM 5.4
CVE-2026-33911
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter…
Openemr
8.0.0.3+
MEDIUM 5.4
CVE-2026-33912
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated a…
Openemr
8.0.0.3+
MEDIUM 5.4
CVE-2026-33348
OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role …
Openemr
8.0.0.3+
MEDIUM 5.4
CVE-2026-2483
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Infosphere Information Server
after 11.7.1.6