Export limit exceeded: 50161 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50161 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39731 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions. | ||||
| CVE-2026-39727 | 2026-10-06 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions. | ||||
| CVE-2026-39726 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. | ||||
| CVE-2026-39724 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions. | ||||
| CVE-2026-39722 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions. | ||||
| CVE-2026-39720 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions. | ||||
| CVE-2026-32577 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions. | ||||
| CVE-2026-32575 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions. | ||||
| CVE-2026-32574 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions. | ||||
| CVE-2026-32572 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions. | ||||
| CVE-2026-32571 | 2026-10-06 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions. | ||||
| CVE-2026-32570 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions. | ||||
| CVE-2026-32569 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions. | ||||
| CVE-2026-105879 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2. | ||||
| CVE-2026-105056 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | ||||
| CVE-2026-104409 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | ||||
| CVE-2026-103346 | 2026-10-06 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | ||||
| CVE-2026-100515 | 2026-10-06 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | ||||
| CVE-2025-15643 | 2026-10-06 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4. | ||||
| CVE-2026-59668 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”. | ||||