Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2026-29100 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML i… Suitecrm 7.15.1+ Fix from $1,6002026-03-19 CRITICAL 9.0 CVE-2026-32751 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via inner… Siyuan 3.6.1+ Fix from $2,3002026-03-19 CRITICAL 9.3 CVE-2026-32754 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scr… Freescout 1.8.209+ Fix from $2,3002026-03-19 MEDIUM 6.1 CVE-2026-32040 OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary … Openclaw 2026.2.23+ Fix from $1,6002026-03-19 HIGH 8.7 CVE-2026-33346 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site script… Openemr 8.0.0.2+ Fix from $1,9502026-03-19 MEDIUM 5.4 CVE-2026-33299 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my… Openemr 8.0.0.2+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-33303 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to … Openemr 8.0.0.2+ Fix from $1,6002026-03-19 MEDIUM 6.1 CVE-2026-27570 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConver… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.1 CVE-2026-27740 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerabilit… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32869 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case informat… Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32866 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated … Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32868 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An a… Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 MEDIUM 5.1 CVE-2026-32843 Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.ph… Mitigation only Fix from $1,6002026-03-19 HIGH 7.1 CVE-2026-27068 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt a… Mitigation only Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-27070 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.T… Mitigation only Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-25438 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks all… Mitigation only Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-25442 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS… Mitigation only Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2025-62043 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa allows DOM-Based XSS.This issue … Mitigation only Fix from $1,6002026-03-19 HIGH 7.1 CVE-2025-67618 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.T… Mitigation only Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-68836 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows R… Mitigation only Fix from $1,9502026-03-19 MEDIUM 5.4 CVE-2026-21788 HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the brow… Connections Mitigation only Fix from $1,6002026-03-19 HIGH 7.1 CVE-2025-50001 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Refle… Mitigation only Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-53222 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription al… Mitigation only Fix from $1,9502026-03-19 MEDIUM 5.4 CVE-2024-42210 A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known … Unica 12.1.9+ Fix from $1,6002026-03-19 MEDIUM 6.4 CVE-2026-4120 The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter with… Mitigation only Fix from $1,6002026-03-19 MEDIUM 6.4 CVE-2026-4006 The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versio… Mitigation only Fix from $1,6002026-03-19 MEDIUM 5.9 CVE-2026-28044 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue… Mitigation only Fix from $1,6002026-03-19 HIGH 7.1 CVE-2026-28073 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected … Mitigation only Fix from $1,9502026-03-19 HIGH 7.2 CVE-2026-1238 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, … Mitigation only Fix from $1,9502026-03-19 MEDIUM 5.4 CVE-2025-15051 IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002026-03-19