CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,778
Total CVEs
248
Critical
2,318
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
934
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 345
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,778)

CVE-2024-47875
10.0

DOMPurify versions before 2.5.0 and 3.1.3 contain a nesting-based mutation XSS (mXSS) vulnerability that allows attackers to bypass HTML sanitization ...

Oct 11, 2024
CVE-2023-45144
10.0

This vulnerability in XWiki's Identity OAuth UI component allows attackers to inject malicious scripts and XWiki syntax via OAuth login parameters. Su...

Oct 16, 2023
CVE-2021-23856
10.0

This vulnerability allows attackers to execute malicious scripts in users' browsers by tricking them into clicking specially crafted URLs. It affects ...

Oct 4, 2021
CVE-2021-39199
10.0

CVE-2021-39199 is a critical cross-site scripting (XSS) vulnerability in the remark-html Node.js library that converts Markdown to HTML. The library i...

Sep 7, 2021
CVE-2021-32798
10.0

CVE-2021-32798 is a critical vulnerability in Jupyter Notebook that allows malicious notebook files to execute arbitrary JavaScript code when opened. ...

Aug 9, 2021
CVE-2021-32671
10.0

This vulnerability in Flarum forum software allows attackers to inject malicious HTML/JavaScript into user input fields, which executes in victims' br...

Jun 7, 2021
CVE-2025-59832
9.9

A stored cross-site scripting (XSS) vulnerability in Horilla HRMS allows low-privilege authenticated users to inject malicious JavaScript into ticket ...

Sep 25, 2025
CVE-2024-24594
9.9

A cross-site scripting (XSS) vulnerability in Allegro AI's ClearML platform allows remote attackers to execute malicious JavaScript when users view th...

Feb 6, 2024
CVE-2023-29205
9.9

This vulnerability allows any XWiki user to inject malicious scripts via the HTML macro, leading to cross-site scripting (XSS) attacks. It affects XWi...

Apr 15, 2023
CVE-2020-7741
9.9

CVE-2020-7741 is a Cross-Site Scripting (XSS) vulnerability in hellojs library versions before 1.18.6. Attackers can inject malicious JavaScript via t...

Oct 6, 2020
CVE-2020-37153
9.8

CVE-2020-37153 allows attackers to execute arbitrary system commands and perform cross-site scripting attacks in ASTPP VoIP billing software. This can...

Feb 11, 2026
CVE-2025-64130
9.8

Zenitel TCIV-3+ devices contain a reflected cross-site scripting (XSS) vulnerability that allows remote attackers to inject and execute arbitrary Java...

Nov 26, 2025
CVE-2025-52161
9.8

This cross-site scripting (XSS) vulnerability in Scholl Communications AG Weblication CMS Core allows attackers to inject malicious scripts into web p...

Sep 8, 2025
CVE-2025-44136
EPSS 10% 9.8

CVE-2025-44136 is a reflected cross-site scripting vulnerability in MapTiler Tileserver-php where the 'layer' GET parameter is not properly sanitized ...

Jul 29, 2025
CVE-2025-46199
9.8

A cross-site scripting (XSS) vulnerability in Grav CMS versions 1.7.48 and earlier allows attackers to inject malicious scripts into form fields. When...

Jul 25, 2025
CVE-2020-26799
9.8

A reflected cross-site scripting (XSS) vulnerability in Luxcal 4.5.2 allows unauthenticated attackers to inject malicious scripts via the index.php pa...

Jul 21, 2025
CVE-2025-53484
9.8

This cross-site scripting (XSS) vulnerability in MediaWiki's SecurePoll extension allows attackers to inject malicious JavaScript through user-control...

Jul 4, 2025
CVE-2025-53599
9.8

This vulnerability allows attackers to execute malicious JavaScript code in Whale browser for iOS by exploiting a flaw in how the browser handles craf...

Jul 4, 2025
CVE-2025-24297
9.8

This vulnerability allows attackers to inject malicious JavaScript code into users' personal spaces of a web portal due to insufficient server-side in...

Apr 15, 2025
CVE-2024-57686
9.8

A reflected Cross-Site Scripting (XSS) vulnerability in PHPGurukul Land Record System v1.0 allows remote attackers to inject malicious scripts via the...

Jan 10, 2025
CVE-2024-52770
9.8

This critical vulnerability in DedeBIZ v6.3.0 allows attackers to upload arbitrary files to the /admin/file_manage_control component, leading to remot...

Nov 20, 2024
CVE-2024-51053
9.8

This vulnerability allows attackers to upload malicious files to AVSCMS v8.2.0 through the /main/fileupload.php component, potentially leading to remo...

Nov 18, 2024
CVE-2023-43091
9.8

CVE-2023-43091 is a critical code injection vulnerability in GNOME Maps that allows arbitrary code execution via malicious service.json configuration ...

Nov 17, 2024
CVE-2024-44081
9.8

This vulnerability in Jitsi Meet allows attackers to inject malicious URLs into video sharing messages, causing clients to load content from arbitrary...

Oct 29, 2024
CVE-2024-8695
9.8

A remote code execution vulnerability in Docker Desktop allows malicious extensions to execute arbitrary code by crafting malicious extension descript...

Sep 12, 2024
CVE-2024-41476
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the /manager/card/card_detail.php endpoint in AMTT Hotel Broadband Opera...

Aug 12, 2024
CVE-2024-40482
9.8

This vulnerability allows attackers to upload arbitrary PHP files to the Kashipara Live Membership System v1.0 via the /Membership/edit_member.php end...

Aug 12, 2024
CVE-2022-32269
9.8

CVE-2022-32269 is a critical vulnerability in Real Player's G2 Control component that allows injection of malicious JavaScript URIs into local HTTP er...

Jun 3, 2022
CVE-2022-28368
9.8

CVE-2022-28368 is a critical remote code execution vulnerability in Dompdf, a PHP library for generating PDFs from HTML. Attackers can exploit this by...

Apr 3, 2022
CVE-2022-0748
9.8

CVE-2022-0748 is a critical vulnerability in post-loader npm package that allows arbitrary JavaScript code execution through malicious markdown input....

Mar 17, 2022
CVE-2021-43439
9.8

CVE-2021-43439 is a remote code execution vulnerability in the Add Review function of iResturant 1.0 that allows unauthenticated attackers to execute ...

Dec 20, 2021
CVE-2025-68669
9.6

This CVE describes a remote code execution vulnerability in the 5ire AI assistant desktop application. The vulnerability allows attackers to execute a...

Dec 23, 2025
CVE-2025-67289
9.6

This critical vulnerability in Frappe Framework's Attachments module allows attackers to upload malicious XML files that can lead to remote code execu...

Dec 22, 2025
CVE-2025-67787
9.6

A Cross-Site Scripting (XSS) vulnerability in DriveLock Operations Center versions 25.1.2 through 25.1.4 allows attackers to inject malicious scripts ...

Dec 17, 2025
CVE-2025-10573
9.6

This stored cross-site scripting (XSS) vulnerability in Ivanti Endpoint Manager allows unauthenticated remote attackers to inject malicious JavaScript...

Dec 9, 2025
CVE-2025-66481
9.6

DeepChat versions 0.5.1 and below are vulnerable to cross-site scripting (XSS) attacks through improperly sanitized Mermaid diagram content. Attackers...

Dec 9, 2025
CVE-2025-64054
9.6

A reflected Cross-Site Scripting (XSS) vulnerability in Fanvil x210 VoIP phones running firmware version 2.12.20 allows attackers to inject malicious ...

Dec 5, 2025
CVE-2025-60739
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server firmware allows remote attackers to execute arbitrary code via the /bh_web_b...

Nov 25, 2025
CVE-2025-11892
9.6

This DOM-based XSS vulnerability in GitHub Enterprise Server allows attackers to execute malicious scripts when users click crafted links in Issues se...

Nov 10, 2025
CVE-2025-56683
9.6

This cross-site scripting (XSS) vulnerability in Logseq v0.10.9 allows attackers to execute arbitrary JavaScript code by injecting malicious scripts i...

Oct 9, 2025
CVE-2025-58357
9.6

CVE-2025-58357 is a content injection vulnerability in 5ire AI assistant that allows attackers to inject malicious content through chat page script ga...

Sep 4, 2025
CVE-2025-5352
9.6

A critical stored XSS vulnerability in lunary-ai/lunary Analytics component allows arbitrary JavaScript execution in all users' browsers when attacker...

Aug 23, 2025
CVE-2025-50128
9.6

A stored cross-site scripting vulnerability in WWBN AVideo allows attackers to inject malicious JavaScript via the videoNotFound 404ErrorMsg parameter...

Jul 24, 2025
CVE-2025-41420
9.6

A cross-site scripting vulnerability in WWBN AVideo's userLogin cancelUri parameter allows attackers to execute arbitrary JavaScript when users visit ...

Jul 24, 2025
CVE-2025-2767
9.6

This critical vulnerability in Arista NG Firewall allows remote attackers to execute arbitrary code with root privileges by exploiting a cross-site sc...

Apr 23, 2025
CVE-2024-55224
9.6

An HTML injection vulnerability in Vaultwarden allows attackers to inject malicious HTML/JavaScript into the username field of email messages. This co...

Jan 9, 2025
CVE-2024-12626
9.6

This vulnerability allows unauthenticated attackers to inject malicious scripts via a specific parameter in the AutomatorWP WordPress plugin. When com...

Dec 19, 2024
CVE-2024-12641
9.6

TenderDocTransfer from Chunghwa Telecom has a reflected cross-site scripting (XSS) vulnerability combined with missing CSRF protection. Unauthenticate...

Dec 16, 2024
CVE-2024-11986
9.6

This vulnerability allows unauthenticated attackers to inject malicious scripts into web application logs via manipulated Host headers. When administr...

Dec 13, 2024
CVE-2024-52053
9.6

This is a stored cross-site scripting (XSS) vulnerability in Wowza Streaming Engine's Manager component that allows unauthenticated attackers to injec...

Nov 21, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,778 CVEs classified as CWE-79, with 248 rated critical and 2,318 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free