Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-33517 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name… Mantisbt Patch available Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-33548 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (… Mantisbt Patch available Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2026-4596 A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. Th… Online Lawyer Management System No fix yet Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-32850 MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to ex… Mailenable 10.55+ Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2025-52204 A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter Mitigation only Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2024-46878 A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability all… Tiki 27.1+ Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2024-46879 A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vuln… Tiki 21.11+ Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2026-33683 WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "abou… Avideo after 26.0 Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-33499 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates… Avideo after 26.0 Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2026-33500 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a cus… Avideo after 26.0 Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2024-51226 A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allo… Vehicle Record Management System No fix yet Fix from $1,6002026-03-23 MEDIUM 6.4 CVE-2025-6229 The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & El… Mitigation only Fix from $1,6002026-03-23 MEDIUM 5.4 CVE-2026-33295 WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plug… Avideo 26.0+ Fix from $1,6002026-03-22 MEDIUM 6.4 CVE-2026-3427 The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `j… Patch available Fix from $1,6002026-03-22 MEDIUM 6.1 CVE-2025-71276 SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. Sogo 5.12.5+ Fix from $1,6002026-03-22 MEDIUM 6.4 CVE-2026-4086 The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-4067 The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and … Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.1 CVE-2026-4069 The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and includi… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-4072 The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-4077 The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in … Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-4084 The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shor… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-4022 The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_type' shortcode … Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3997 The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] short… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3996 The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3617 The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' shortcode attributes in all versio… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3619 The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute in the [sheets2table-render-t… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3554 The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in all vers… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.5 CVE-2026-3347 The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[message]` parameter in all vers… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.4 CVE-2026-3333 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up … Mitigation only Fix from $1,6002026-03-21 HIGH 7.2 CVE-2026-3003 The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, an… Mitigation only Fix from $1,9502026-03-21