CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,806)
An open redirect vulnerability in Plane project management software allows attackers to inject malicious JavaScript via the ?next_path query parameter...
Oct 24, 2025Authenticated users in RISE Ultimate Project Manager & CRM can inject malicious HTML into invoices and messages. This content renders in emails, PDFs,...
Oct 10, 2025This reflected XSS vulnerability in tawk.to chatbox widget v4 allows attackers to inject malicious JavaScript that executes in users' browsers when th...
Sep 29, 2025This stored cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute OpenAtlas allows attackers to inject malicious scripts into ...
Aug 4, 2025DuraComm SPM-500 DP-10iN-100-MU devices are vulnerable to cross-site scripting (XSS) attacks that could allow attackers to inject malicious scripts in...
Jul 22, 2025This vulnerability allows attackers to inject malicious scripts into the 'Attachments by filename keyword' report feature in ManageEngine Exchange Rep...
Jun 26, 2025Discourse versions before 3.5.0.beta6 are vulnerable to cross-site scripting (XSS) when social logins are used without Content Security Policy (CSP) e...
Jun 25, 2025Real Estate Management 1.0 contains a stored cross-site scripting (XSS) vulnerability in the /store/index.php endpoint. This allows attackers to injec...
Jun 18, 2025This vulnerability in Dot desktop application allows cross-site scripting (XSS) attacks that can lead to remote code execution. Attackers can inject m...
Jun 2, 2025Pega Platform versions 8.4.3 through Infinity 24.2.1 contain a cross-site scripting (XSS) vulnerability in the Mashup component. This allows attackers...
Apr 14, 2025This Cross-Site Scripting (XSS) vulnerability in CtrlPanel allows attackers to inject malicious scripts into the moderator panel by manipulating the p...
Feb 11, 2025Wegia versions below 3.2.0 contain a cross-site scripting vulnerability in the employee documents page that allows attackers to inject malicious scrip...
Jan 17, 2025This vulnerability in grist-core allows cross-site scripting (XSS) attacks via malicious SVG attachments. When a user previews an attachment containin...
Dec 20, 2024This vulnerability allows attackers to inject malicious scripts into Optimizely Configured Commerce search history, which then execute in users' brows...
Dec 18, 2024MobSF versions before 4.2.9 have a stored XSS vulnerability in the 'Diff or Compare' functionality. Attackers can upload malicious script files that e...
Dec 3, 2024A reflected XSS vulnerability in @dapperduckling/keycloak-connector-server allows attackers to execute arbitrary JavaScript in victims' browsers by tr...
Nov 26, 2024This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to inject malicious scripts...
Jul 24, 2024This vulnerability allows cross-site scripting (XSS) attacks in React applications using Plate media editor. Attackers can inject malicious JavaScript...
Jul 15, 2024CVE-2024-38354 is a cross-site scripting (XSS) vulnerability in CodiMD/HackMD's notebook feature that allows attackers to inject malicious scripts via...
Jul 10, 2024This vulnerability allows an admin user in Splunk Enterprise and Splunk Cloud Platform to store and execute arbitrary JavaScript code in other users' ...
Jul 1, 2024Stored Cross-Site Scripting (XSS) vulnerabilities in OpenText ArcSight Logger allow attackers to inject malicious scripts that persist in the applicat...
Jun 11, 2024SAP Business Objects Business Intelligence Platform contains a stored cross-site scripting (XSS) vulnerability in the Opendocument URL parameter. Atta...
May 14, 2024The MM-email2image WordPress plugin through version 0.2.5 contains a stored cross-site scripting (XSS) vulnerability due to improper input validation ...
Apr 26, 2024CVE-2024-28233 is a cross-site scripting (XSS) vulnerability in JupyterHub that allows attackers to achieve full access to the JupyterHub API and user...
Mar 27, 2024This CVE describes a cross-site scripting (XSS) vulnerability in Honeywell MPA2 Access Panel web server modules. Attackers can inject malicious script...
Feb 29, 2024This stored cross-site scripting (XSS) vulnerability in PAC Device web interfaces allows administrators to inject malicious scripts into form fields. ...
Nov 28, 2023This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator allows authenticated attackers to inject malicious scripts into the web interface. Wh...
Aug 22, 2023This cross-site scripting (XSS) vulnerability in Intel DSA software allows unauthenticated attackers to inject malicious scripts via network access. I...
Aug 11, 2023This cross-site scripting (XSS) vulnerability in Intel Manageability Commander software allows unauthenticated attackers to inject malicious scripts v...
Aug 11, 2023A persistent cross-site scripting (XSS) vulnerability in Unica Campaign allows attackers to inject malicious scripts into a specific field. When users...
Aug 3, 2023This CVE describes a persistent cross-site scripting (XSS) vulnerability in a specific field of the Unica Platform. An attacker can inject malicious s...
Aug 3, 2023CVE-2023-34089 is a cross-site scripting (XSS) vulnerability in Decidim's processes filter feature that allows remote attackers to execute JavaScript ...
Jul 11, 2023CVE-2023-32693 is a cross-site scripting (XSS) vulnerability in Decidim's external link feature that allows remote attackers to execute JavaScript in ...
Jul 11, 2023CVE-2023-32686 is a cross-site scripting (XSS) vulnerability in Kiwi TCMS that allows attackers to bypass file upload validation and upload malicious ...
May 27, 2023CVE-2023-23467 is a reflected cross-site scripting (XSS) vulnerability in Media CP Media Control Panel that allows attackers to inject malicious scrip...
Feb 15, 2023This vulnerability allows remote attackers to execute arbitrary shell commands with root privileges on affected Baicells cellular base stations via HT...
Feb 11, 2023This cross-site scripting (XSS) vulnerability in Johnson Controls Metasys building automation systems allows attackers to inject malicious scripts int...
Jun 15, 2022This vulnerability allows remote attackers to upload malicious files disguised as images to the admin interface, which can then trigger cross-site scr...
Apr 26, 2022This stored XSS vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form fields. When users visi...
Jan 13, 2022This vulnerability allows authenticated attackers with object modification privileges to inject malicious HTML/JavaScript into the TopEase® Platform'...
Nov 30, 2021CVE-2021-21422 is a cross-site scripting (XSS) vulnerability in mongo-express web interface that allows attackers to execute arbitrary JavaScript in a...
Jun 21, 2021CVE-2021-32641 is a reflected cross-site scripting (XSS) vulnerability in Auth0's Lock authentication widget. Attackers can inject malicious scripts v...
Jun 4, 2021This is a cross-site scripting (XSS) vulnerability in 1CDN file sharing software that allows attackers to inject malicious JavaScript code. When explo...
May 28, 2021This stored cross-site scripting (XSS) vulnerability in Magento allows attackers to inject malicious JavaScript into customer address uploads. When ex...
Feb 11, 2021This vulnerability allows cross-site scripting (XSS) attacks in MarkUs assignment submission system. Attackers can inject malicious scripts into stude...
Mar 5, 2026This vulnerability allows unauthenticated attackers to inject arbitrary scripts into GitLab's Mermaid diagram sandbox UI, potentially leading to cross...
Feb 25, 2026This stored cross-site scripting (XSS) vulnerability in Jenkins allows attackers with Agent/Configure or Agent/Disconnect permissions to inject malici...
Feb 18, 2026A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...
Feb 2, 2026A stored XSS vulnerability in Altium Workflow Engine allows authenticated users to inject malicious JavaScript into workflow data. When administrators...
Jan 15, 2026HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist ...
Jan 10, 2026About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,806 CVEs classified as CWE-79, with 260 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free