Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 430/454
7.1
CVE-2023-33999

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Lo

7.1
CVE-2026-42653

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP

7.1
CVE-2026-3840

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin

7.1
CVE-2026-47120

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be

7.1
CVE-2026-48119

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to b

7.1
CVE-2026-49396

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be

7.1
CVE-2019-25746

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attacker

7.1
CVE-2026-5230

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Inco

7.1
CVE-2026-5233

Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issu

7.1
CVE-2026-52719

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser rea

7.1
CVE-2026-52722

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor d

7.1
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file,

7.1
CVE-2026-53704

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file cont

7.1
CVE-2025-68840

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

7.1
CVE-2025-68851

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

7.1
CVE-2025-68872

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

7.1
CVE-2026-23970

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

7.1
CVE-2026-34900

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.

7.1
CVE-2026-34902

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.

7.1
CVE-2026-39435

Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.

7.1
CVE-2026-39447

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.

7.1
CVE-2026-39449

Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

7.1
CVE-2026-39450

Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

7.1
CVE-2026-39463

Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

7.1
CVE-2026-39507

Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.

7.1
CVE-2026-39514

Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

7.1
CVE-2026-39518

Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.

7.1
CVE-2026-40732

Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.

7.1
CVE-2026-40770

Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.

7.1
CVE-2026-40785

Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

7.1
CVE-2026-40787

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.

7.1
CVE-2026-40788

Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.

7.1
CVE-2026-40791

Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.

7.1
CVE-2026-42649

Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.

7.1
CVE-2026-42658

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.

7.1
CVE-2026-42686

Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.

7.1
CVE-2026-42775

Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.

7.1
CVE-2026-45437

Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.

7.1
CVE-2026-48838

Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.

7.1
CVE-2026-48867

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.

7.1
CVE-2026-48871

Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.

7.1
CVE-2026-48876

Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.

7.1
CVE-2026-48885

Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.

7.1
CVE-2026-48966

Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.

7.1
CVE-2026-49055

Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.

7.1
CVE-2026-52702

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

7.1
CVE-2026-39437

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

7.1
CVE-2026-54191

Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

7.1
CVE-2026-54198

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

7.1
CVE-2026-53840

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started