CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,809
Total CVEs
261
Critical
2,331
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 59
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,809)

CVE-2026-1010
8.0

A stored XSS vulnerability in Altium Workflow Engine allows authenticated users to inject malicious JavaScript into workflow data. When administrators...

Jan 15, 2026
CVE-2026-22704
8.0

HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist ...

Jan 10, 2026
CVE-2025-13761
8.0

This is a cross-site scripting (XSS) vulnerability in GitLab that allows an unauthenticated attacker to execute arbitrary JavaScript code in the conte...

Jan 9, 2026
CVE-2025-12029
8.0

This vulnerability allows unauthenticated attackers to inject malicious scripts into GitLab's Swagger UI interface, potentially enabling them to perfo...

Dec 11, 2025
CVE-2025-67495
8.0

ZITADEL versions 4.0.0-rc.1 through 4.7.0 have a DOM-based XSS vulnerability in the logout endpoint. Unauthenticated attackers can execute malicious J...

Dec 9, 2025
CVE-2025-62618
8.0

This vulnerability in ELOG allows authenticated users to upload HTML files that execute in other users' contexts, potentially stealing credentials. It...

Oct 31, 2025
CVE-2025-64112
8.0

CVE-2025-64112 is a stored cross-site scripting (XSS) vulnerability in Statmatic CMS that allows authenticated users with content creation permissions...

Oct 30, 2025
CVE-2025-55742
8.0

UnoPim versions before 0.2.1 contain a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts via SVG files at th...

Aug 21, 2025
CVE-2025-5806
8.0

The Jenkins Gatling Plugin 136.vb_9009b_3d33a_e has a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into ...

Jun 6, 2025
CVE-2024-13919
8.0

Laravel applications running vulnerable versions are susceptible to reflected cross-site scripting (XSS) attacks when debug mode is enabled. Attackers...

Mar 10, 2025
CVE-2024-13918
8.0

Laravel framework versions 11.9.0 through 11.35.1 contain a reflected cross-site scripting vulnerability in debug-mode error pages. Attackers can inje...

Mar 10, 2025
CVE-2025-24320
8.0

A stored XSS vulnerability in BIG-IP Configuration utility allows attackers to execute JavaScript in the context of logged-in users. This affects BIG-...

Feb 5, 2025
CVE-2024-54003
8.0

Jenkins Simple Queue Plugin 1.4.4 and earlier contains a stored cross-site scripting (XSS) vulnerability where attackers with View/Create permission c...

Nov 27, 2024
CVE-2024-52951
8.0

This stored cross-site scripting (XSS) vulnerability in Omada Identity allows authenticated attackers to inject malicious scripts into the Access Requ...

Nov 27, 2024
CVE-2024-52552
8.0

The Jenkins Authorize Project Plugin 1.7.2 and earlier contains a stored cross-site scripting (XSS) vulnerability where attackers with Item/Configure ...

Nov 13, 2024
CVE-2024-4835
8.0

This is a cross-site scripting (XSS) vulnerability in GitLab that allows attackers to create malicious web pages that can steal sensitive user informa...

May 23, 2024
CVE-2024-31156
8.0

This stored XSS vulnerability in the BIG-IP Configuration utility allows attackers to inject malicious JavaScript that executes when legitimate users ...

May 8, 2024
CVE-2024-29184
8.0

A stored cross-site scripting (XSS) vulnerability in FreeScout's signature input field allows support agents to inject malicious JavaScript that execu...

Mar 22, 2024
CVE-2024-28404
8.0

This stored cross-site scripting (XSS) vulnerability in TOTOLINK X2000R routers allows attackers to inject malicious scripts into the MAC Filtering co...

Mar 15, 2024
CVE-2024-28157
8.0

The Jenkins GitBucket Plugin 0.8 and earlier contains a stored cross-site scripting (XSS) vulnerability where GitBucket URLs displayed on build views ...

Mar 6, 2024
CVE-2023-43658
8.0

This vulnerability in the discourse-calendar plugin allows attackers to inject malicious scripts into event titles, leading to cross-site scripting (X...

Oct 16, 2023
CVE-2023-26218
8.0

This CVE describes a reflected cross-site scripting (XSS) vulnerability in TIBCO Nimbus Web Client that allows attackers to trick authenticated users ...

Sep 29, 2023
CVE-2023-0625
8.0

This vulnerability in Docker Desktop allows remote code execution (RCE) when a malicious extension description or changelog is processed. Attackers ca...

Sep 25, 2023
CVE-2023-29183
8.0

This cross-site scripting (XSS) vulnerability in Fortinet's FortiProxy and FortiOS web management interfaces allows authenticated attackers to inject ...

Sep 13, 2023
CVE-2023-36891
8.0

This vulnerability allows an attacker to inject malicious scripts into Microsoft SharePoint Server, which could execute when viewed by other users. It...

Aug 8, 2023
CVE-2023-30860
8.0

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo's meeting scheduling feature. Attackers can inject malicious scripts into mee...

May 8, 2023
CVE-2023-27474
8.0

Directus instances using allow-listed password reset URLs are vulnerable to HTML injection attacks via query parameters. Attackers can craft malicious...

Mar 6, 2023
CVE-2022-22769
8.0

This CVE describes a stored cross-site scripting (XSS) vulnerability in TIBCO EBX web server components. It allows low-privileged attackers with netwo...

Jan 19, 2022
CVE-2021-43764
8.0

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form ...

Jan 13, 2022
CVE-2021-43761
8.0

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) allows attackers to inject malicious scripts into form fields, ...

Jan 13, 2022
CVE-2022-0121
8.0

This CVE describes a cross-site scripting (XSS) vulnerability in hoppscotch, an API development tool. Attackers can inject malicious scripts into web ...

Jan 6, 2022
CVE-2021-35499
8.0

This stored XSS vulnerability in TIBCO Nimbus Web Reporting allows low-privileged attackers to inject malicious scripts that execute when legitimate u...

Oct 26, 2021
CVE-2021-31355
8.0

This persistent cross-site scripting (XSS) vulnerability in Juniper Junos OS captive portal GUI allows authenticated remote attackers to inject malici...

Oct 19, 2021
CVE-2021-22528
8.0

This vulnerability allows attackers to execute malicious JavaScript in users' browsers through NetIQ Access Manager web interfaces. It affects organiz...

Sep 13, 2021
CVE-2021-35222
8.0

CVE-2021-35222 is a reflected cross-site scripting (XSS) vulnerability in SolarWinds Orion Platform that allows attackers to impersonate authenticated...

Aug 31, 2021
CVE-2021-37710
8.0

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Shopware eCommerce platform that allows attackers to inject malicious scripts via SVG...

Aug 16, 2021
CVE-2021-32702
8.0

The Auth0 Next.js SDK versions 1.4.1 and lower contain a reflected cross-site scripting (XSS) vulnerability. Attackers can inject malicious JavaScript...

Jun 25, 2021
CVE-2021-23273
8.0

This vulnerability allows low-privileged attackers with network access to execute stored cross-site scripting (XSS) attacks in TIBCO Spotfire products...

Mar 9, 2021
CVE-2021-23271
8.0

This vulnerability allows low-privileged attackers with network access to execute stored cross-site scripting (XSS) attacks against TIBCO EBX Web Serv...

Feb 2, 2021
CVE-2025-40890
7.9

A stored XSS vulnerability in Dashboards functionality allows authenticated low-privilege users to inject malicious JavaScript into dashboards. When v...

Nov 25, 2025
CVE-2024-12755
7.9

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces allows attackers to inject malicious scripts into web pages viewed by other users. This cou...

Feb 11, 2025
CVE-2023-49145
7.9

This DOM-based cross-site scripting vulnerability in Apache NiFi's JoltTransformJSON Processor allows authenticated users with configuration privilege...

Nov 27, 2023
CVE-2023-41471
7.8

This CVE describes a cross-site scripting (XSS) vulnerability in copyparty versions before 1.9.2 that allows a local attacker with write access to exe...

Aug 29, 2025
CVE-2025-24028
7.8

This is a cross-site scripting (XSS) vulnerability in Joplin's Rich Text Editor caused by differences between Joplin's HTML sanitizer and browser comm...

Feb 7, 2025
CVE-2025-25187
7.8

This vulnerability in Joplin allows attackers to execute arbitrary code on a user's system by injecting malicious JavaScript into note titles. Users w...

Feb 7, 2025
CVE-2025-13523
7.7

This cross-site scripting (XSS) vulnerability in Mattermost's Confluence plugin allows authenticated Confluence users with malicious display names to ...

Feb 6, 2026
CVE-2025-11224
7.7

This vulnerability allows authenticated users to execute stored cross-site scripting (XSS) attacks through improper input validation in GitLab's Kuber...

Jan 14, 2026
CVE-2025-8459
7.7

This stored XSS vulnerability in Centreon Infra Monitoring allows attackers to inject malicious scripts into web pages through the recurrent downtime ...

Oct 14, 2025
CVE-2025-0555
7.7

This Cross-Site Scripting (XSS) vulnerability in GitLab Enterprise Edition allows attackers to bypass security controls and execute malicious scripts ...

Mar 3, 2025
CVE-2024-52595
7.7

This vulnerability in lxml_html_clean allows attackers to bypass HTML sanitization by exploiting differences in how browsers versus the library parse ...

Nov 19, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,809 CVEs classified as CWE-79, with 261 rated critical and 2,331 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free