CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,805
Total CVEs
259
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,805)

CVE-2022-43760
8.4

This stored XSS vulnerability in SUSE Rancher allows authenticated users with write permissions to inject malicious scripts that execute in administra...

Jun 1, 2023
CVE-2023-0786
8.4

This CVE describes a cross-site scripting (XSS) vulnerability in phpMyFAQ software versions prior to 3.1.11. Attackers can inject malicious scripts in...

Feb 12, 2023
CVE-2021-31848
8.4

This is a cross-site scripting (XSS) vulnerability in McAfee Data Loss Prevention ePO extension that allows remote attackers to hijack active administ...

Nov 1, 2021
CVE-2021-32737
8.4

This vulnerability allows authenticated admin users in Sulu CMS to inject malicious scripts into collection titles, leading to cross-site scripting (X...

Jul 2, 2021
CVE-2025-52482
8.3

A stored cross-site scripting (XSS) vulnerability in Chamilo LMS allows teachers to inject malicious JavaScript into the glossary function, which exec...

Mar 2, 2026
CVE-2025-10913
8.3

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Saastech Cleaning and Internet Services Inc.'s TemizlikYolda software. Attackers can ...

Feb 11, 2026
CVE-2025-64675
8.3

This cross-site scripting (XSS) vulnerability in Azure Cosmos DB allows attackers to inject malicious scripts into web pages generated by the database...

Dec 19, 2025
CVE-2025-62459
8.3

This vulnerability allows attackers to spoof content in the Microsoft Defender portal through cross-site scripting (XSS). It affects organizations usi...

Nov 20, 2025
CVE-2025-60880
8.3

An authenticated stored XSS vulnerability in Bagisto 2.3.6 allows admin users to upload malicious SVG files containing JavaScript code. When viewed, t...

Oct 10, 2025
CVE-2025-29471
EPSS 16% 8.3

A Cross-Site Scripting (XSS) vulnerability in Nagios Log Server v.2024R1.3.1 allows remote attackers to inject malicious scripts via the Email field. ...

Apr 15, 2025
CVE-2025-26529
8.3

This stored cross-site scripting (XSS) vulnerability in Moodle's site administration live log allows attackers to inject malicious scripts that execut...

Feb 24, 2025
CVE-2025-26530
8.3

This reflected cross-site scripting (XSS) vulnerability in Moodle's question bank filter allows attackers to inject malicious scripts into web pages v...

Feb 24, 2025
CVE-2025-22597
8.3

A stored XSS vulnerability in WeGIA's CobrancaController.php endpoint allows attackers to inject malicious scripts via the local_recepcao parameter. T...

Jan 10, 2025
CVE-2025-22598
8.3

A stored XSS vulnerability in WeGIA's cadastrarSocio.php endpoint allows attackers to inject malicious scripts into the local_recepcao parameter. Thes...

Jan 10, 2025
CVE-2025-22132
8.3

This Cross-Site Scripting (XSS) vulnerability in WeGIA's file upload functionality allows attackers to upload malicious files containing JavaScript co...

Jan 7, 2025
CVE-2017-20192
8.3

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress forms created with the Formidable Form Builder plugin. ...

Oct 16, 2024
CVE-2024-47061
8.3

CVE-2024-47061 is a security vulnerability in Plate JavaScript toolkit that allows malicious actors to inject custom DOM attributes, potentially leadi...

Sep 20, 2024
CVE-2024-4749
8.3

This vulnerability in the wp-eMember WordPress plugin allows attackers to inject malicious scripts via the 'fieldId' parameter, which are then execute...

Jun 4, 2024
CVE-2024-3323
8.3

This is a cross-site scripting (XSS) vulnerability in TIBCO JasperReports Server that allows attackers to inject malicious scripts into the applicatio...

Apr 17, 2024
CVE-2023-40000
8.3

This vulnerability allows unauthenticated attackers to inject malicious scripts into web pages generated by LiteSpeed Cache, leading to stored cross-s...

Apr 16, 2024
CVE-2023-40288
8.3

This Cross-Site Scripting (XSS) vulnerability affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F devices running firmware version 1.66. An attacker c...

Mar 27, 2024
CVE-2023-40290
8.3

This Cross-Site Scripting (XSS) vulnerability affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F BMC/IPMI firmware version 1.66. Attackers can inject...

Mar 27, 2024
CVE-2023-40284
8.3

This Cross-Site Scripting (XSS) vulnerability affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F BMC/IPMI firmware version 1.66. An attacker could in...

Mar 27, 2024
CVE-2023-40286
8.3

This Cross-Site Scripting (XSS) vulnerability affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F BMC/IPMI firmware version 1.66. An attacker could in...

Mar 27, 2024
CVE-2024-22397
8.3

This stored cross-site scripting (XSS) vulnerability in SonicOS SSLVPN portal allows authenticated admin users to inject and execute arbitrary JavaScr...

Mar 14, 2024
CVE-2023-49277
8.3

This vulnerability in dpaste allows attackers to execute arbitrary JavaScript in users' browsers via a reflected XSS attack through the expires parame...

Dec 1, 2023
CVE-2023-35796
8.3

This vulnerability in SINEMA Server V14 allows attackers to execute stored cross-site scripting attacks through improperly sanitized SNMP configuratio...

Oct 10, 2023
CVE-2023-40047
8.3

This stored XSS vulnerability in WS_FTP Server allows attackers with administrative privileges to inject malicious JavaScript via SSL certificate impo...

Sep 27, 2023
CVE-2023-40045
8.3

This reflected cross-site scripting (XSS) vulnerability in WS_FTP Server's Ad Hoc Transfer module allows attackers to execute malicious JavaScript in ...

Sep 27, 2023
CVE-2023-37496
8.3

HCL Verse contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When victims vi...

Aug 1, 2023
CVE-2023-28083
8.3

A cross-site scripting (XSS) vulnerability in HPE Integrated Lights-Out (iLO) management interfaces allows attackers to inject malicious scripts that ...

Mar 22, 2023
CVE-2021-22978
8.3

This vulnerability is a reflected cross-site scripting (XSS) attack in the iControl REST interface of F5 BIG-IP devices. Attackers can craft malicious...

Feb 12, 2021
CVE-2026-26723
8.2

A Cross-Site Scripting (XSS) vulnerability in Key Systems Inc Global Facilities Management Software allows remote attackers to inject malicious script...

Feb 20, 2026
CVE-2026-25847
8.2

A DOM-based cross-site scripting (XSS) vulnerability in JetBrains PyCharm's Jupyter viewer page allows attackers to execute arbitrary JavaScript in th...

Feb 9, 2026
CVE-2025-67823
8.2

An unauthenticated cross-site scripting (XSS) vulnerability in Mitel's Multimedia Email component allows attackers to execute arbitrary scripts in vic...

Jan 15, 2026
CVE-2025-66444
8.2

This CVE describes a cross-site scripting (XSS) vulnerability in Hitachi's Infrastructure Analytics Advisor and Ops Center Analyzer products. Attacker...

Dec 24, 2025
CVE-2025-64677
8.2

This cross-site scripting (XSS) vulnerability in Microsoft Office Out-of-Box Experience allows attackers to inject malicious scripts into web pages. W...

Dec 18, 2025
CVE-2025-66492
8.2

This Cross-Site Scripting (XSS) vulnerability in Masa CMS allows attackers to inject malicious scripts via the ajax URL query parameter. When exploite...

Dec 12, 2025
CVE-2025-63057
8.2

This DOM-based cross-site scripting vulnerability in the WP Ultimate Review WordPress plugin allows attackers to inject malicious scripts that execute...

Dec 9, 2025
CVE-2025-25017
8.2

This CVE describes a cross-site scripting (XSS) vulnerability in Kibana where improper input sanitization during web page generation allows attackers ...

Oct 10, 2025
CVE-2025-29192
8.2

This Cross-Site Scripting (XSS) vulnerability in Flowise allows attackers to inject malicious scripts via FORM and INPUT elements in chat logs. When a...

Oct 6, 2025
CVE-2025-59430
8.2

The Mesh Connect JS SDK prior to version 3.3.2 contains a cross-site scripting (XSS) vulnerability in the createLink.openLink function due to insuffic...

Sep 22, 2025
CVE-2025-52187
8.2

CVE-2025-52187 is a stored cross-site scripting (XSS) vulnerability in GetProjectsIdea Create School Management System 1.0 that allows attackers to in...

Jul 30, 2025
CVE-2025-53923
8.2

Emlog website building system contains a cross-site scripting (XSS) vulnerability in the keyword parameter that allows attackers to inject malicious J...

Jul 16, 2025
CVE-2025-47977
8.2

This cross-site scripting (XSS) vulnerability in Nuance Digital Engagement Platform allows attackers to inject malicious scripts into web pages viewed...

Jun 10, 2025
CVE-2025-22249
8.2

This DOM-based XSS vulnerability in VMware Aria Automation allows attackers to steal authenticated users' access tokens by tricking them into clicking...

May 13, 2025
CVE-2025-0984
8.2

This vulnerability in Netoloji Software E-Flow allows attackers to upload dangerous files and execute stored cross-site scripting attacks. It affects ...

May 6, 2025
CVE-2025-2609
8.2

An unauthenticated cross-site scripting (XSS) vulnerability in MagnusBilling's login logging component allows attackers to inject malicious HTML/JavaS...

Mar 21, 2025
CVE-2025-27500
8.2

CVE-2025-27500 is an authentication bypass vulnerability in OpenZiti's admin panel that allows unauthenticated attackers to upload malicious files to ...

Mar 3, 2025
CVE-2025-27088
8.2

A reflected cross-site scripting (XSS) vulnerability in oxyno-zeta/s3-proxy allows attackers to craft malicious URLs that inject scripts into the web ...

Feb 20, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,805 CVEs classified as CWE-79, with 259 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free