CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,809)
A stored XSS vulnerability in Altium Workflow Engine allows authenticated users to inject malicious JavaScript into workflow data. When administrators...
Jan 15, 2026HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist ...
Jan 10, 2026This is a cross-site scripting (XSS) vulnerability in GitLab that allows an unauthenticated attacker to execute arbitrary JavaScript code in the conte...
Jan 9, 2026This vulnerability allows unauthenticated attackers to inject malicious scripts into GitLab's Swagger UI interface, potentially enabling them to perfo...
Dec 11, 2025ZITADEL versions 4.0.0-rc.1 through 4.7.0 have a DOM-based XSS vulnerability in the logout endpoint. Unauthenticated attackers can execute malicious J...
Dec 9, 2025This vulnerability in ELOG allows authenticated users to upload HTML files that execute in other users' contexts, potentially stealing credentials. It...
Oct 31, 2025CVE-2025-64112 is a stored cross-site scripting (XSS) vulnerability in Statmatic CMS that allows authenticated users with content creation permissions...
Oct 30, 2025UnoPim versions before 0.2.1 contain a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts via SVG files at th...
Aug 21, 2025The Jenkins Gatling Plugin 136.vb_9009b_3d33a_e has a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into ...
Jun 6, 2025Laravel applications running vulnerable versions are susceptible to reflected cross-site scripting (XSS) attacks when debug mode is enabled. Attackers...
Mar 10, 2025Laravel framework versions 11.9.0 through 11.35.1 contain a reflected cross-site scripting vulnerability in debug-mode error pages. Attackers can inje...
Mar 10, 2025A stored XSS vulnerability in BIG-IP Configuration utility allows attackers to execute JavaScript in the context of logged-in users. This affects BIG-...
Feb 5, 2025Jenkins Simple Queue Plugin 1.4.4 and earlier contains a stored cross-site scripting (XSS) vulnerability where attackers with View/Create permission c...
Nov 27, 2024This stored cross-site scripting (XSS) vulnerability in Omada Identity allows authenticated attackers to inject malicious scripts into the Access Requ...
Nov 27, 2024The Jenkins Authorize Project Plugin 1.7.2 and earlier contains a stored cross-site scripting (XSS) vulnerability where attackers with Item/Configure ...
Nov 13, 2024This is a cross-site scripting (XSS) vulnerability in GitLab that allows attackers to create malicious web pages that can steal sensitive user informa...
May 23, 2024This stored XSS vulnerability in the BIG-IP Configuration utility allows attackers to inject malicious JavaScript that executes when legitimate users ...
May 8, 2024A stored cross-site scripting (XSS) vulnerability in FreeScout's signature input field allows support agents to inject malicious JavaScript that execu...
Mar 22, 2024This stored cross-site scripting (XSS) vulnerability in TOTOLINK X2000R routers allows attackers to inject malicious scripts into the MAC Filtering co...
Mar 15, 2024The Jenkins GitBucket Plugin 0.8 and earlier contains a stored cross-site scripting (XSS) vulnerability where GitBucket URLs displayed on build views ...
Mar 6, 2024This vulnerability in the discourse-calendar plugin allows attackers to inject malicious scripts into event titles, leading to cross-site scripting (X...
Oct 16, 2023This CVE describes a reflected cross-site scripting (XSS) vulnerability in TIBCO Nimbus Web Client that allows attackers to trick authenticated users ...
Sep 29, 2023This vulnerability in Docker Desktop allows remote code execution (RCE) when a malicious extension description or changelog is processed. Attackers ca...
Sep 25, 2023This cross-site scripting (XSS) vulnerability in Fortinet's FortiProxy and FortiOS web management interfaces allows authenticated attackers to inject ...
Sep 13, 2023This vulnerability allows an attacker to inject malicious scripts into Microsoft SharePoint Server, which could execute when viewed by other users. It...
Aug 8, 2023This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo's meeting scheduling feature. Attackers can inject malicious scripts into mee...
May 8, 2023Directus instances using allow-listed password reset URLs are vulnerable to HTML injection attacks via query parameters. Attackers can craft malicious...
Mar 6, 2023This CVE describes a stored cross-site scripting (XSS) vulnerability in TIBCO EBX web server components. It allows low-privileged attackers with netwo...
Jan 19, 2022This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form ...
Jan 13, 2022This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) allows attackers to inject malicious scripts into form fields, ...
Jan 13, 2022This CVE describes a cross-site scripting (XSS) vulnerability in hoppscotch, an API development tool. Attackers can inject malicious scripts into web ...
Jan 6, 2022This stored XSS vulnerability in TIBCO Nimbus Web Reporting allows low-privileged attackers to inject malicious scripts that execute when legitimate u...
Oct 26, 2021This persistent cross-site scripting (XSS) vulnerability in Juniper Junos OS captive portal GUI allows authenticated remote attackers to inject malici...
Oct 19, 2021This vulnerability allows attackers to execute malicious JavaScript in users' browsers through NetIQ Access Manager web interfaces. It affects organiz...
Sep 13, 2021CVE-2021-35222 is a reflected cross-site scripting (XSS) vulnerability in SolarWinds Orion Platform that allows attackers to impersonate authenticated...
Aug 31, 2021This CVE describes a Cross-Site Scripting (XSS) vulnerability in Shopware eCommerce platform that allows attackers to inject malicious scripts via SVG...
Aug 16, 2021The Auth0 Next.js SDK versions 1.4.1 and lower contain a reflected cross-site scripting (XSS) vulnerability. Attackers can inject malicious JavaScript...
Jun 25, 2021This vulnerability allows low-privileged attackers with network access to execute stored cross-site scripting (XSS) attacks in TIBCO Spotfire products...
Mar 9, 2021This vulnerability allows low-privileged attackers with network access to execute stored cross-site scripting (XSS) attacks against TIBCO EBX Web Serv...
Feb 2, 2021A stored XSS vulnerability in Dashboards functionality allows authenticated low-privilege users to inject malicious JavaScript into dashboards. When v...
Nov 25, 2025A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces allows attackers to inject malicious scripts into web pages viewed by other users. This cou...
Feb 11, 2025This DOM-based cross-site scripting vulnerability in Apache NiFi's JoltTransformJSON Processor allows authenticated users with configuration privilege...
Nov 27, 2023This CVE describes a cross-site scripting (XSS) vulnerability in copyparty versions before 1.9.2 that allows a local attacker with write access to exe...
Aug 29, 2025This is a cross-site scripting (XSS) vulnerability in Joplin's Rich Text Editor caused by differences between Joplin's HTML sanitizer and browser comm...
Feb 7, 2025This vulnerability in Joplin allows attackers to execute arbitrary code on a user's system by injecting malicious JavaScript into note titles. Users w...
Feb 7, 2025This cross-site scripting (XSS) vulnerability in Mattermost's Confluence plugin allows authenticated Confluence users with malicious display names to ...
Feb 6, 2026This vulnerability allows authenticated users to execute stored cross-site scripting (XSS) attacks through improper input validation in GitLab's Kuber...
Jan 14, 2026This stored XSS vulnerability in Centreon Infra Monitoring allows attackers to inject malicious scripts into web pages through the recurrent downtime ...
Oct 14, 2025This Cross-Site Scripting (XSS) vulnerability in GitLab Enterprise Edition allows attackers to bypass security controls and execute malicious scripts ...
Mar 3, 2025This vulnerability in lxml_html_clean allows attackers to bypass HTML sanitization by exploiting differences in how browsers versus the library parse ...
Nov 19, 2024About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,809 CVEs classified as CWE-79, with 261 rated critical and 2,331 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free