Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-33738 Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and re… Lychee 7.5.3+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33742 Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 a… Invoice Ninja 5.13.4+ Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-3528 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scr… Calculation Fields 1.0.4+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33628 Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja… Invoice Ninja 5.13.4+ Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-33525 Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via … Authelia No fix yet Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-29969 A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Jav… Staffwiki No fix yet Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-34071 Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version 2.7.3, the /api/v1/convert/em… Stirling Pdf No fix yet Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-33402 Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contai… Sakai 23.5 / 25.2+ Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-29934 A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript … Lightcms No fix yet Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-30162 Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field. Timo No fix yet Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-29933 A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascri… Yzmcms No fix yet Fix from $1,6002026-03-26 HIGH 8.7 CVE-2026-28297 SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint… Observability Self Hosted 2026.1.1+ Fix from $1,9502026-03-26 HIGH 8.1 CVE-2026-28298 SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint… Observability Self Hosted 2026.1.1+ Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-2231 The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.… Mitigation only Fix from $1,9502026-03-26 MEDIUM 6.1 CVE-2025-41027 Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br… Gdtaller Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2025-41026 Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's br… Gdtaller Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2018-25210 WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to m… E Ticaret after 4.0.0 Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-4849 A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component … Simple Laundry System No fix yet Fix from $1,6002026-03-26 HIGH 7.2 CVE-2026-4329 The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and… Mitigation only Fix from $1,9502026-03-26 MEDIUM 6.4 CVE-2026-4389 The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` … Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.4 CVE-2026-4278 The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and… Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.4 CVE-2026-4075 The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up t… Mitigation only Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-4335 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to,… Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-1986 The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.1 CVE-2026-33933 OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to ver… Openemr 8.0.0.3+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33932 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-sit… Openemr 8.0.0.3+ Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-33911 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter… Openemr 8.0.0.3+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-33912 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated a… Openemr 8.0.0.3+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-33348 OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role … Openemr 8.0.0.3+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-2483 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25