Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Thunderbird MEDIUM 6.5
CVE-2026-57963

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the ch…

Fix: 140.12.1 / 152.0.1+
Fix from $1,600 2026-07-01
Focus HIGH 7.5
CVE-2026-11799

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

Fix: 151.3.1+
Fix from $1,950 2026-06-09
Firefox MEDIUM 5.4
CVE-2026-9308

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a…

Fix: 151.2+
Fix from $1,600 2026-06-01
Firefox MEDIUM 5.4
CVE-2026-9309

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View beha…

Fix: 151.2+
Fix from $1,600 2026-06-01
Firefox CRITICAL 9.1
CVE-2026-8948

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $2,300 2026-05-19
Firefox MEDIUM 5.3
CVE-2026-8391

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…

Fix: 150.0.3+
Fix from $1,600 2026-05-12
Firefox MEDIUM 5.3
CVE-2026-6779

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox HIGH 8.1
CVE-2025-10534

Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

Fix: 143.0+
Fix from $1,950 2025-09-16
Firefox Focus MEDIUM 6.1
CVE-2025-55033

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vuln…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox MEDIUM 6.1
CVE-2025-6430

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>…

Fix: 128.12.0 / 140.0+
Fix from $1,600 2025-06-24
Thunderbird MEDIUM 5.4
CVE-2025-1015

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containin…

Fix: 128.7.0+
Fix from $1,600 2025-02-04
Firefox MEDIUM 6.1
CVE-2024-11694

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shi…

Fix: 115.8.0 / 115.18.0+
Fix from $1,600 2024-11-26
Nunjucks MEDIUM 6.1
CVE-2023-2142

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If ther…

Fix: 3.2.4+
Fix from $1,600 2024-11-26
Firefox MEDIUM 6.1
CVE-2024-10461

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, whic…

Fix: 128.4.0 / 132.0+
Fix from $1,600 2024-10-29
Firefox HIGH 7.5
CVE-2024-9394

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow…

Fix: 115.16.0 / 128.3+
Fix from $1,950 2024-10-01
Firefox MEDIUM 6.1
CVE-2024-43111

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for…

Fix: 129+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.1
CVE-2024-43112

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Fix: 129+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.1
CVE-2024-43113

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

Fix: 129+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.1
CVE-2024-7524

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Secur…

Fix: 115.14 / 128.1+
Fix from $1,600 2024-08-06
Firefox HIGH 8.2
CVE-2024-4776

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox Focus MEDIUM 6.1
CVE-2024-26284

Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to t…

Fix: 123.0+
Fix from $1,600 2024-02-22
Firefox Focus MEDIUM 6.1
CVE-2024-0606

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthoriz…

Fix: 122.0+
Fix from $1,600 2024-01-22
Firefox MEDIUM 6.1
CVE-2023-5758

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS…

Fix: 119.0+
Fix from $1,600 2023-10-25
Common Voice MEDIUM 6.1
CVE-2023-42808

Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for traini…

No fix yet
Fix from $1,600 2023-10-04
Firefox MEDIUM 6.1
CVE-2019-17003

Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.

Fix: after 25.0
Fix from $1,600 2023-02-16
Bleach MEDIUM 6.1
CVE-2021-23980

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script…

Fix: 3.3.0+
Fix from $1,600 2023-02-16
Firefox MEDIUM 6.1
CVE-2022-45411

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and …

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45408

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, re…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-40956

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vuln…

Fix: 102.3 / 105.0+
Fix from $1,600 2022-12-22
Thunderbird HIGH 8.1
CVE-2022-3033

If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv=…

Fix: 91.13.1 / 102.2.1+
Fix from $1,950 2022-12-22