Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2026-33411 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a potential stored XSS in topic tit… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33230 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan… Nltk after 3.9.3 Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33209 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exist… Avo 3.30.3+ Fix from $1,6002026-03-20 HIGH 8.7 CVE-2026-33172 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r… Statamic 5.73.14 / 6.7.0+ Fix from $1,9502026-03-20 MEDIUM 6.1 CVE-2026-33140 PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and pri… Pyspector 0.1.7+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2025-63260 SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message. Syncfusion No fix yet Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-32844 XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attack… Php Api Doc after 2019-03-24 Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-30578 File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbit… File Thingie Mitigation only Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-30579 File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a… File Thingie Mitigation only Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-29828 DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc. Dootask after 1.6.27 Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-32986 Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploit… Textpattern No fix yet Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33370 An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase… Zimbra Collaboration Suite 10.1.16+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33368 Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/… Zimbra Collaboration Suite 10.1.16+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-31382 The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload. Assist No fix yet Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33135 WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_me… Wegia 3.6.7+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33136 WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_… Wegia 3.6.7+ Fix from $1,6002026-03-20 MEDIUM 5.9 CVE-2024-31119 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyllou Special Box for Content a… Mitigation only Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33080 Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two … Filament 4.8.5 / 5.3.5+ Fix from $1,6002026-03-20 CRITICAL 9.0 CVE-2026-33066 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS… Siyuan 3.6.1+ Fix from $2,3002026-03-20 CRITICAL 9.0 CVE-2026-33067 SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l… Siyuan 3.6.1+ Fix from $2,3002026-03-20 MEDIUM 5.4 CVE-2026-33061 Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80ef… Jexactyl after 3.8.0 Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-4474 A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.… University Management System No fix yet Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33051 Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor render… Craft Cms 5.9.11+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-33035 WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attacker… Avideo 26.0+ Fix from $1,6002026-03-20 MEDIUM 6.1 CVE-2026-32940 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and… Siyuan 3.6.1+ Fix from $1,6002026-03-20 CRITICAL 9.6 CVE-2026-32890 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and… Anchorr after 1.4.1 Fix from $2,3002026-03-20 MEDIUM 6.4 CVE-2026-32880 ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaSc… Churchcrm 7.0.2+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-32757 Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value inst… Admidio 5.0.7+ Fix from $1,6002026-03-20 MEDIUM 5.4 CVE-2026-33395 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discourse-graphviz plugin contains … Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.1 CVE-2026-29106 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the val… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,6002026-03-19