CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,805
Total CVEs
259
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,805)

CVE-2024-47604
8.2

CVE-2024-47604 is a cross-site scripting (XSS) vulnerability in NuGet Gallery that allows attackers to inject malicious HTML or JavaScript through HTM...

Oct 1, 2024
CVE-2024-45592
8.2

This vulnerability allows attackers to inject and execute malicious JavaScript code in Symfony applications using auditor-bundle. The issue affects al...

Sep 10, 2024
CVE-2024-21690
8.2

This high-severity vulnerability in Confluence Data Center and Server allows unauthenticated attackers to execute reflected XSS attacks and CSRF attac...

Aug 21, 2024
CVE-2023-38506
8.2

Joplin note-taking application has a cross-site scripting (XSS) vulnerability where pasting untrusted HTML into the rich text editor can execute arbit...

Jun 21, 2024
CVE-2024-4856
8.2

The FS Product Inquiry WordPress plugin through version 1.1.1 contains a reflected cross-site scripting (XSS) vulnerability. Attackers can inject mali...

Jun 4, 2024
CVE-2024-4776
8.2

A vulnerability in Firefox allows a file dialog displayed during full-screen mode to leave the window disabled, potentially enabling clickjacking atta...

May 14, 2024
CVE-2024-33303
8.2

SourceCodester Product Show Room 1.0 contains a stored cross-site scripting (XSS) vulnerability in the 'First Name' field when adding users. This allo...

May 2, 2024
CVE-2023-44852
8.2

This Cross-Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku satellite communication systems allows remote attackers to inject malicious scr...

Apr 12, 2024
CVE-2024-2050
8.2

This CVE describes a cross-site scripting (XSS) vulnerability in Schneider Electric products where attackers can inject and execute malicious JavaScri...

Mar 18, 2024
CVE-2024-21395
8.2

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victim...

Feb 13, 2024
CVE-2024-23893
8.2

CVE-2024-23893 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23896
8.2

CVE-2024-23896 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory software version 1.0. An attacker can inject mal...

Jan 26, 2024
CVE-2024-23891
8.2

This is a Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows remote attackers to inject malicious scri...

Jan 26, 2024
CVE-2024-23885
8.2

CVE-2024-23885 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows remote attackers to inje...

Jan 26, 2024
CVE-2024-23887
8.2

CVE-2024-23887 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows remote attackers to inje...

Jan 26, 2024
CVE-2024-23889
8.2

CVE-2024-23889 is a stored cross-site scripting (XSS) vulnerability in Cups Easy version 1.0 that allows remote attackers to inject malicious scripts ...

Jan 26, 2024
CVE-2024-23881
8.2

CVE-2024-23881 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy version 1.0 that allows remote attackers to inject malicious scripts ...

Jan 26, 2024
CVE-2024-23883
8.2

CVE-2024-23883 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23875
8.2

CVE-2024-23875 is a stored cross-site scripting (XSS) vulnerability in Cups Easy version 1.0 that allows attackers to inject malicious scripts via the...

Jan 26, 2024
CVE-2024-23877
8.2

CVE-2024-23877 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows remote attackers to inje...

Jan 26, 2024
CVE-2024-23879
8.2

CVE-2024-23879 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23869
8.2

This is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory software version 1.0. It allows remote attackers to inject...

Jan 26, 2024
CVE-2024-23871
8.2

CVE-2024-23871 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23873
8.2

CVE-2024-23873 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23865
8.2

CVE-2024-23865 is a stored cross-site scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0. Attackers can inject malicious scri...

Jan 26, 2024
CVE-2024-23867
8.2

CVE-2024-23867 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows remote attackers to inje...

Jan 26, 2024
CVE-2024-23863
8.2

CVE-2024-23863 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory version 1.0 that allows attackers to inject mali...

Jan 26, 2024
CVE-2024-23859
8.2

This is a Cross-Site Scripting (XSS) vulnerability in Cups Easy Purchase & Inventory software version 1.0 that allows attackers to inject malicious sc...

Jan 26, 2024
CVE-2024-23861
8.2

CVE-2024-23861 is a stored Cross-Site Scripting (XSS) vulnerability in Cups Easy version 1.0 that allows remote attackers to inject malicious scripts ...

Jan 26, 2024
CVE-2024-23857
8.2

CVE-2024-23857 is a Cross-Site Scripting (XSS) vulnerability in Cups Easy (Purchase & Inventory) version 1.0 that allows remote attackers to inject ma...

Jan 26, 2024
CVE-2023-30563
8.2

This vulnerability allows attackers to upload malicious files through the System Manager User Import Function, which can lead to session hijacking. It...

Jul 13, 2023
CVE-2023-33991
8.2

This CVE describes a stored cross-site scripting (XSS) vulnerability in SAP UI5 Variant Management where user-controlled inputs are not properly encod...

Jun 13, 2023
CVE-2023-33186
8.2

This cross-site scripting (XSS) vulnerability in Zulip Server allows attackers to inject malicious JavaScript into topic tooltips. When a victim hover...

May 30, 2023
CVE-2023-0835
8.2

CVE-2023-0835 is a path traversal vulnerability in markdown-pdf version 11.0.0 that allows attackers to read arbitrary local files by injecting malici...

Apr 4, 2023
CVE-2023-27472
8.2

This is a cross-site scripting (XSS) vulnerability in quickentity-editor-next, a local video game asset editor. It allows attackers to execute arbitra...

Mar 6, 2023
CVE-2022-22999
8.2

Western Digital My Cloud devices contain a cross-site scripting (XSS) vulnerability that allows authenticated attackers with elevated privileges to in...

Jul 25, 2022
CVE-2022-24833
8.2

This CVE describes a cross-site scripting (XSS) vulnerability in PrivateBin where malicious SVG attachments containing JavaScript can execute arbitrar...

Apr 11, 2022
CVE-2021-43856
8.2

Wiki.js versions 2.5.263 and earlier are vulnerable to stored cross-site scripting (XSS) through malicious non-image file uploads. An authenticated at...

Dec 27, 2021
CVE-2021-39183
8.2

This vulnerability in Owncast allows cross-site scripting (XSS) attacks when users paste content containing inline JavaScript. Attackers can execute a...

Dec 14, 2021
CVE-2021-27910
8.2

CVE-2021-27910 is a stored cross-site scripting (XSS) vulnerability in Mautic's bounce management callback function. Attackers can inject malicious Ja...

Aug 30, 2021
CVE-2026-25136
8.1

This is a reflected Cross-site Scripting (XSS) vulnerability in Rucio's WebUI that allows attackers to steal login session tokens. Attackers can craft...

Feb 25, 2026
CVE-2026-27196
8.1

This stored cross-site scripting (XSS) vulnerability in Statmatic CMS allows authenticated users with field management permissions to inject malicious...

Feb 21, 2026
CVE-2025-65110
8.1

This vulnerability in Vega visualization library allows arbitrary JavaScript execution via DOM-based XSS when applications meet two conditions: they a...

Jan 5, 2026
CVE-2025-68147
8.1

A stored XSS vulnerability in Open Source Point of Sale allows attackers with administrative access to inject malicious JavaScript into the Return Pol...

Dec 17, 2025
CVE-2025-65778
8.1

This vulnerability allows attackers to upload malicious attachments that are served with HTML content types, enabling cross-site scripting (XSS) attac...

Dec 15, 2025
CVE-2025-13614
8.1

The Cool Tag Cloud WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to inje...

Dec 5, 2025
CVE-2025-13639
8.1

This vulnerability in Chrome's WebRTC implementation allows attackers to perform arbitrary read/write operations via a crafted HTML page. It affects u...

Dec 2, 2025
CVE-2025-59840
8.1

This vulnerability allows arbitrary JavaScript code execution in Vega visualization applications when two specific conditions are met: the application...

Nov 13, 2025
CVE-2025-63307
8.1

CVE-2025-63307 is a Cross-Site Scripting (XSS) vulnerability in alexusmai/laravel-file-manager version 3.3.1 that allows attackers to upload malicious...

Nov 6, 2025
CVE-2025-62716
8.1

An open redirect vulnerability in Plane project management software allows attackers to inject malicious JavaScript via the ?next_path query parameter...

Oct 24, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,805 CVEs classified as CWE-79, with 259 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free