CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,806
Total CVEs
260
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,806)

CVE-2025-62716
8.1

An open redirect vulnerability in Plane project management software allows attackers to inject malicious JavaScript via the ?next_path query parameter...

Oct 24, 2025
CVE-2025-60378
8.1

Authenticated users in RISE Ultimate Project Manager & CRM can inject malicious HTML into invoices and messages. This content renders in emails, PDFs,...

Oct 10, 2025
CVE-2025-57483
8.1

This reflected XSS vulnerability in tawk.to chatbox widget v4 allows attackers to inject malicious JavaScript that executes in users' browsers when th...

Sep 29, 2025
CVE-2025-51534
8.1

This stored cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute OpenAtlas allows attackers to inject malicious scripts into ...

Aug 4, 2025
CVE-2025-41425
8.1

DuraComm SPM-500 DP-10iN-100-MU devices are vulnerable to cross-site scripting (XSS) attacks that could allow attackers to inject malicious scripts in...

Jul 22, 2025
CVE-2025-5966
8.1

This vulnerability allows attackers to inject malicious scripts into the 'Attachments by filename keyword' report feature in ManageEngine Exchange Rep...

Jun 26, 2025
CVE-2025-48954
EPSS 15.6% 8.1

Discourse versions before 3.5.0.beta6 are vulnerable to cross-site scripting (XSS) when social logins are used without Content Security Policy (CSP) e...

Jun 25, 2025
CVE-2025-45786
8.1

Real Estate Management 1.0 contains a stored cross-site scripting (XSS) vulnerability in the /store/index.php endpoint. This allows attackers to injec...

Jun 18, 2025
CVE-2024-57783
8.1

This vulnerability in Dot desktop application allows cross-site scripting (XSS) attacks that can lead to remote code execution. Attackers can inject m...

Jun 2, 2025
CVE-2025-2160
8.1

Pega Platform versions 8.4.3 through Infinity 24.2.1 contain a cross-site scripting (XSS) vulnerability in the Mashup component. This allows attackers...

Apr 14, 2025
CVE-2025-25203
8.1

This Cross-Site Scripting (XSS) vulnerability in CtrlPanel allows attackers to inject malicious scripts into the moderator panel by manipulating the p...

Feb 11, 2025
CVE-2024-57030
8.1

Wegia versions below 3.2.0 contain a cross-site scripting vulnerability in the employee documents page that allows attackers to inject malicious scrip...

Jan 17, 2025
CVE-2024-56358
8.1

This vulnerability in grist-core allows cross-site scripting (XSS) attacks via malicious SVG attachments. When a user previews an attachment containin...

Dec 20, 2024
CVE-2024-56174
8.1

This vulnerability allows attackers to inject malicious scripts into Optimizely Configured Commerce search history, which then execute in users' brows...

Dec 18, 2024
CVE-2024-53999
8.1

MobSF versions before 4.2.9 have a stored XSS vulnerability in the 'Diff or Compare' functionality. Attackers can upload malicious script files that e...

Dec 3, 2024
CVE-2024-53843
8.1

A reflected XSS vulnerability in @dapperduckling/keycloak-connector-server allows attackers to execute arbitrary JavaScript in victims' browsers by tr...

Nov 26, 2024
CVE-2024-41914
8.1

This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to inject malicious scripts...

Jul 24, 2024
CVE-2024-40631
8.1

This vulnerability allows cross-site scripting (XSS) attacks in React applications using Plate media editor. Attackers can inject malicious JavaScript...

Jul 15, 2024
CVE-2024-38354
8.1

CVE-2024-38354 is a cross-site scripting (XSS) vulnerability in CodiMD/HackMD's notebook feature that allows attackers to inject malicious scripts via...

Jul 10, 2024
CVE-2024-36997
8.1

This vulnerability allows an admin user in Splunk Enterprise and Splunk Cloud Platform to store and execute arbitrary JavaScript code in other users' ...

Jul 1, 2024
CVE-2024-4190
8.1

Stored Cross-Site Scripting (XSS) vulnerabilities in OpenText ArcSight Logger allow attackers to inject malicious scripts that persist in the applicat...

Jun 11, 2024
CVE-2024-28165
8.1

SAP Business Objects Business Intelligence Platform contains a stored cross-site scripting (XSS) vulnerability in the Opendocument URL parameter. Atta...

May 14, 2024
CVE-2024-3075
8.1

The MM-email2image WordPress plugin through version 0.2.5 contains a stored cross-site scripting (XSS) vulnerability due to improper input validation ...

Apr 26, 2024
CVE-2024-28233
8.1

CVE-2024-28233 is a cross-site scripting (XSS) vulnerability in JupyterHub that allows attackers to achieve full access to the JupyterHub API and user...

Mar 27, 2024
CVE-2023-1841
8.1

This CVE describes a cross-site scripting (XSS) vulnerability in Honeywell MPA2 Access Panel web server modules. Attackers can inject malicious script...

Feb 29, 2024
CVE-2023-4667
8.1

This stored cross-site scripting (XSS) vulnerability in PAC Device web interfaces allows administrators to inject malicious scripts into form fields. ...

Nov 28, 2023
CVE-2023-37422
8.1

This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator allows authenticated attackers to inject malicious scripts into the web interface. Wh...

Aug 22, 2023
CVE-2023-27515
8.1

This cross-site scripting (XSS) vulnerability in Intel DSA software allows unauthenticated attackers to inject malicious scripts via network access. I...

Aug 11, 2023
CVE-2022-29887
8.1

This cross-site scripting (XSS) vulnerability in Intel Manageability Commander software allows unauthenticated attackers to inject malicious scripts v...

Aug 11, 2023
CVE-2023-37501
8.1

A persistent cross-site scripting (XSS) vulnerability in Unica Campaign allows attackers to inject malicious scripts into a specific field. When users...

Aug 3, 2023
CVE-2023-37499
8.1

This CVE describes a persistent cross-site scripting (XSS) vulnerability in a specific field of the Unica Platform. An attacker can inject malicious s...

Aug 3, 2023
CVE-2023-34089
8.1

CVE-2023-34089 is a cross-site scripting (XSS) vulnerability in Decidim's processes filter feature that allows remote attackers to execute JavaScript ...

Jul 11, 2023
CVE-2023-32693
8.1

CVE-2023-32693 is a cross-site scripting (XSS) vulnerability in Decidim's external link feature that allows remote attackers to execute JavaScript in ...

Jul 11, 2023
CVE-2023-32686
8.1

CVE-2023-32686 is a cross-site scripting (XSS) vulnerability in Kiwi TCMS that allows attackers to bypass file upload validation and upload malicious ...

May 27, 2023
CVE-2023-23467
8.1

CVE-2023-23467 is a reflected cross-site scripting (XSS) vulnerability in Media CP Media Control Panel that allows attackers to inject malicious scrip...

Feb 15, 2023
CVE-2023-0776
8.1

This vulnerability allows remote attackers to execute arbitrary shell commands with root privileges on affected Baicells cellular base stations via HT...

Feb 11, 2023
CVE-2022-21938
8.1

This cross-site scripting (XSS) vulnerability in Johnson Controls Metasys building automation systems allows attackers to inject malicious scripts int...

Jun 15, 2022
CVE-2021-26628
8.1

This vulnerability allows remote attackers to upload malicious files disguised as images to the admin interface, which can then trigger cross-site scr...

Apr 26, 2022
CVE-2021-44176
8.1

This stored XSS vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form fields. When users visi...

Jan 13, 2022
CVE-2021-42118
8.1

This vulnerability allows authenticated attackers with object modification privileges to inject malicious HTML/JavaScript into the TopEase® Platform'...

Nov 30, 2021
CVE-2021-21422
8.1

CVE-2021-21422 is a cross-site scripting (XSS) vulnerability in mongo-express web interface that allows attackers to execute arbitrary JavaScript in a...

Jun 21, 2021
CVE-2021-32641
8.1

CVE-2021-32641 is a reflected cross-site scripting (XSS) vulnerability in Auth0's Lock authentication widget. Attackers can inject malicious scripts v...

Jun 4, 2021
CVE-2021-32616
8.1

This is a cross-site scripting (XSS) vulnerability in 1CDN file sharing software that allows attackers to inject malicious JavaScript code. When explo...

May 28, 2021
CVE-2021-21030
8.1

This stored cross-site scripting (XSS) vulnerability in Magento allows attackers to inject malicious JavaScript into customer address uploads. When ex...

Feb 11, 2021
CVE-2026-28405
8.0

This vulnerability allows cross-site scripting (XSS) attacks in MarkUs assignment submission system. Attackers can inject malicious scripts into stude...

Mar 5, 2026
CVE-2026-0752
8.0

This vulnerability allows unauthenticated attackers to inject arbitrary scripts into GitLab's Mermaid diagram sandbox UI, potentially leading to cross...

Feb 25, 2026
CVE-2026-27099
8.0

This stored cross-site scripting (XSS) vulnerability in Jenkins allows attackers with Agent/Configure or Agent/Disconnect permissions to inject malici...

Feb 18, 2026
CVE-2026-23997
8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...

Feb 2, 2026
CVE-2026-1010
8.0

A stored XSS vulnerability in Altium Workflow Engine allows authenticated users to inject malicious JavaScript into workflow data. When administrators...

Jan 15, 2026
CVE-2026-22704
8.0

HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist ...

Jan 10, 2026

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,806 CVEs classified as CWE-79, with 260 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free