CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,812
Total CVEs
261
Critical
2,334
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 59
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,812)

CVE-2024-52595
7.7

This vulnerability in lxml_html_clean allows attackers to bypass HTML sanitization by exploiting differences in how browsers versus the library parse ...

Nov 19, 2024
CVE-2024-45594
7.7

This Cross-Site Scripting (XSS) vulnerability in Decidim's meeting embeds feature allows attackers to inject malicious scripts through specially craft...

Nov 13, 2024
CVE-2024-6379
7.7

A reflected Cross-site Scripting (XSS) vulnerability in 3DSwymer component of 3DEXPERIENCE platform allows attackers to inject malicious scripts that ...

Aug 20, 2024
CVE-2024-7047
7.7

This cross-site scripting vulnerability in GitLab allows attackers to inject malicious scripts that execute in the context of authenticated users. All...

Jul 25, 2024
CVE-2024-30248
7.7

Piccolo Admin versions before 1.3.2 allow SVG file uploads by default, which can contain malicious scripts. When an attacker uploads a crafted SVG fil...

Apr 2, 2024
CVE-2023-37520
7.7

An unauthenticated stored cross-site scripting (XSS) vulnerability in BigFix Server version 9.5.12.68 allows attackers to inject malicious scripts int...

Dec 21, 2023
CVE-2023-37519
7.7

CVE-2023-37519 is an unauthenticated stored cross-site scripting (XSS) vulnerability in the Download Status Report feature of BigFix Server. Attackers...

Dec 21, 2023
CVE-2023-25825
7.7

ZoneMinder versions before 1.36.33 are vulnerable to stored cross-site scripting (XSS) through malicious referrer field injection in database logs. Wh...

Feb 25, 2023
CVE-2022-33934
7.7

Dell PowerScale OneFS versions 8.2.x through 9.4.x contain stored cross-site scripting (XSS) vulnerabilities. Remote authenticated users with high pri...

Feb 10, 2023
CVE-2022-1940
7.7

This is a stored cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition's Jira integration. It allows attackers to inject malicious Jav...

Jun 6, 2022
CVE-2022-22773
7.7

This CVE describes a reflected cross-site scripting (XSS) vulnerability in TIBCO JasperReports Server's REST API. A low-privileged attacker with netwo...

May 17, 2022
CVE-2020-25163
7.7

This vulnerability allows remote attackers with write access to PI ProcessBook files to inject malicious code that executes when imported into OSIsoft...

Apr 18, 2022
CVE-2021-28807
7.7

This is a post-authentication reflected cross-site scripting (XSS) vulnerability in QNAP's Q'center management software. It allows authenticated attac...

Jun 3, 2021
CVE-2021-32818
7.7

CVE-2021-32818 is a template injection vulnerability in haml-coffee JavaScript templating engine that allows remote code execution and cross-site scri...

May 14, 2021
CVE-2020-26249
7.7

CVE-2020-26249 is a remote code execution vulnerability in Red Discord Bot Dashboard that allows attackers to inject malicious code through specially ...

Dec 9, 2020
CVE-2026-25802
7.6

This vulnerability allows attackers to inject malicious scripts via model outputs containing <script> tags in New API's MarkdownRenderer.jsx component...

Feb 24, 2026
CVE-2026-27013
7.6

Fabric.js versions before 7.2.0 have an SVG export vulnerability where user-controlled JSON data isn't properly escaped when converted to SVG. This al...

Feb 19, 2026
CVE-2025-40587
7.6

This vulnerability allows authenticated attackers to inject malicious JavaScript into document titles in Polarion applications. When other users view ...

Feb 10, 2026
CVE-2025-7760
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Ofisimo's Association Web Package Flora software that allows attackers to inject mali...

Feb 3, 2026
CVE-2025-8456
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Kod8 Individual and SME Website software that allows attackers to inject malicious scr...

Feb 3, 2026
CVE-2025-8461
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Seres Software syWEB that allows attackers to inject malicious scripts into web pages....

Feb 3, 2026
CVE-2025-8589
7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can inject malicious scripts into...

Feb 3, 2026
CVE-2026-24837
7.6

This vulnerability allows attackers to inject malicious scripts into DNN module friendly names, which then execute during certain Persona Bar operatio...

Jan 28, 2026
CVE-2026-24833
7.6

This vulnerability allows attackers to inject malicious scripts into DNN module descriptions, which then execute in the Persona Bar administration int...

Jan 28, 2026
CVE-2026-24836
7.6

This vulnerability allows stored cross-site scripting (XSS) attacks in DNN CMS. Attackers with extension permissions can inject malicious scripts into...

Jan 28, 2026
CVE-2025-27380
7.6

This vulnerability allows authenticated attackers to inject malicious HTML content into Project Release functionality in Altium Enterprise Server. Whe...

Jan 22, 2026
CVE-2026-1008
7.6

A stored XSS vulnerability in Altium 365 user profile fields allows authenticated attackers to inject malicious scripts that execute when other users ...

Jan 15, 2026
CVE-2025-2307
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Verisay's Aidango software that allows attackers to inject malicious scripts into web...

Dec 25, 2025
CVE-2025-2405
7.6

This is a cross-site scripting (XSS) vulnerability in Titarus software from Verisay Communication and Information Technology Industry and Trade Ltd. C...

Dec 25, 2025
CVE-2025-2406
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Trizbi software by Verisay Communication and Information Technology Industry and Trad...

Dec 25, 2025
CVE-2025-65027
7.6

RomM (ROM Manager) versions before 4.4.1 contain multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious ...

Dec 3, 2025
CVE-2025-66468
7.6

This CVE describes a stored cross-site scripting (XSS) vulnerability in the Aimeos GrapesJS CMS extension. Malicious editors can inject JavaScript cod...

Dec 2, 2025
CVE-2025-64501
7.6

The prosemirror_to_html gem versions 0.2.0 and below are vulnerable to Cross-Site Scripting (XSS) attacks through malicious HTML attribute values. Whi...

Nov 10, 2025
CVE-2025-10914
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Proliz Software's OBS Student Affairs Information System. Attackers can inject malicio...

Oct 23, 2025
CVE-2025-61597
7.6

Emlog versions 2.5.21 and below contain a stored cross-site scripting (XSS) vulnerability in mail template settings. An attacker with admin access can...

Oct 3, 2025
CVE-2025-45805
7.6

CVE-2025-45805 is a stored cross-site scripting (XSS) vulnerability in phpgurukul Doctor Appointment Management System 1.0. Authenticated doctor users...

Sep 3, 2025
CVE-2025-8092
7.6

This vulnerability allows attackers to inject malicious scripts into web pages generated by Drupal's COOKiES Consent Management module, which could ex...

Aug 15, 2025
CVE-2025-51624
7.6

A cross-site scripting (XSS) vulnerability in Zone Bitaqati allows attackers to inject malicious scripts into web pages viewed by other users. This af...

Aug 6, 2025
CVE-2025-51504
7.6

Microweber CMS 2.0 contains a stored cross-site scripting (XSS) vulnerability in the profile page's last name field. This allows attackers to inject m...

Aug 1, 2025
CVE-2025-53528
7.6

CVE-2025-53528 is a reflected cross-site scripting (XSS) vulnerability in Cadwyn's API documentation endpoint. An attacker can craft a malicious URL c...

Jul 21, 2025
CVE-2025-52902
7.6

File Browser versions prior to 2.33.7 have a stored cross-site scripting (XSS) vulnerability in the Markdown preview function. When users upload Markd...

Jun 26, 2025
CVE-2025-49262
7.6

This stored cross-site scripting (XSS) vulnerability in the Sina Extension for Elementor WordPress plugin allows attackers to inject malicious scripts...

Jun 6, 2025
CVE-2025-32794
7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient creation privileges can inject malicious JavaSc...

May 23, 2025
CVE-2025-43860
7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient editing privileges can inject malicious JavaScr...

May 23, 2025
CVE-2025-4123
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Grafana that combines client path traversal with open redirect. Attackers can redirec...

May 22, 2025
CVE-2025-3246
7.6

A cross-site scripting vulnerability in GitHub Enterprise Server allows attackers to inject malicious scripts into math blocks using $$..$$ delimiters...

Apr 17, 2025
CVE-2025-27406
7.6

This vulnerability in Icinga Reporting allows attackers to embed arbitrary JavaScript in report templates. When previewed, this enables attackers to a...

Mar 26, 2025
CVE-2025-27404
7.6

This is a cross-site scripting (XSS) vulnerability in Icinga Web 2 that allows attackers to craft malicious URLs. When any user visits such a URL, arb...

Mar 26, 2025
CVE-2025-2610
7.6

An authenticated stored cross-site scripting (XSS) vulnerability in MagnusBilling's Alarm Module allows attackers to inject malicious scripts that exe...

Mar 21, 2025
CVE-2024-11824
7.6

A stored XSS vulnerability in langgenius/dify's chat log functionality allows attackers to inject malicious HTML tags like <input> and <form> via prom...

Mar 20, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,812 CVEs classified as CWE-79, with 261 rated critical and 2,334 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free