CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,863
Total CVEs
273
Critical
2,373
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,863)

CVE-2020-26210
7.7

This vulnerability allows authenticated users with page edit permissions in BookStack to inject malicious JavaScript links into pages. When other user...

Nov 3, 2020
CVE-2026-25802
7.6

This vulnerability allows attackers to inject malicious scripts via model outputs containing <script> tags in New API's MarkdownRenderer.jsx component...

Feb 24, 2026
CVE-2026-27013
7.6

Fabric.js versions before 7.2.0 have an SVG export vulnerability where user-controlled JSON data isn't properly escaped when converted to SVG. This al...

Feb 19, 2026
CVE-2025-40587
7.6

This vulnerability allows authenticated attackers to inject malicious JavaScript into document titles in Polarion applications. When other users view ...

Feb 10, 2026
CVE-2025-7760
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Ofisimo's Association Web Package Flora software that allows attackers to inject mali...

Feb 3, 2026
CVE-2025-8456
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Kod8 Individual and SME Website software that allows attackers to inject malicious scr...

Feb 3, 2026
CVE-2025-8461
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Seres Software syWEB that allows attackers to inject malicious scripts into web pages....

Feb 3, 2026
CVE-2025-8589
7.6

This CVE describes a reflected cross-site scripting (XSS) vulnerability in AKCE Software's SKSPro product. Attackers can inject malicious scripts into...

Feb 3, 2026
CVE-2026-24837
7.6

This vulnerability allows attackers to inject malicious scripts into DNN module friendly names, which then execute during certain Persona Bar operatio...

Jan 28, 2026
CVE-2026-24833
7.6

This vulnerability allows attackers to inject malicious scripts into DNN module descriptions, which then execute in the Persona Bar administration int...

Jan 28, 2026
CVE-2026-24836
7.6

This vulnerability allows stored cross-site scripting (XSS) attacks in DNN CMS. Attackers with extension permissions can inject malicious scripts into...

Jan 28, 2026
CVE-2025-27380
7.6

This vulnerability allows authenticated attackers to inject malicious HTML content into Project Release functionality in Altium Enterprise Server. Whe...

Jan 22, 2026
CVE-2026-1008
7.6

A stored XSS vulnerability in Altium 365 user profile fields allows authenticated attackers to inject malicious scripts that execute when other users ...

Jan 15, 2026
CVE-2025-2307
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Verisay's Aidango software that allows attackers to inject malicious scripts into web...

Dec 25, 2025
CVE-2025-2405
7.6

This is a cross-site scripting (XSS) vulnerability in Titarus software from Verisay Communication and Information Technology Industry and Trade Ltd. C...

Dec 25, 2025
CVE-2025-2406
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Trizbi software by Verisay Communication and Information Technology Industry and Trad...

Dec 25, 2025
CVE-2025-65027
7.6

RomM (ROM Manager) versions before 4.4.1 contain multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious ...

Dec 3, 2025
CVE-2025-66468
7.6

This CVE describes a stored cross-site scripting (XSS) vulnerability in the Aimeos GrapesJS CMS extension. Malicious editors can inject JavaScript cod...

Dec 2, 2025
CVE-2025-64501
7.6

The prosemirror_to_html gem versions 0.2.0 and below are vulnerable to Cross-Site Scripting (XSS) attacks through malicious HTML attribute values. Whi...

Nov 10, 2025
CVE-2025-10914
7.6

This is a reflected cross-site scripting (XSS) vulnerability in Proliz Software's OBS Student Affairs Information System. Attackers can inject malicio...

Oct 23, 2025
CVE-2025-61597
7.6

Emlog versions 2.5.21 and below contain a stored cross-site scripting (XSS) vulnerability in mail template settings. An attacker with admin access can...

Oct 3, 2025
CVE-2025-45805
7.6

CVE-2025-45805 is a stored cross-site scripting (XSS) vulnerability in phpgurukul Doctor Appointment Management System 1.0. Authenticated doctor users...

Sep 3, 2025
CVE-2025-8092
7.6

This vulnerability allows attackers to inject malicious scripts into web pages generated by Drupal's COOKiES Consent Management module, which could ex...

Aug 15, 2025
CVE-2025-51624
7.6

A cross-site scripting (XSS) vulnerability in Zone Bitaqati allows attackers to inject malicious scripts into web pages viewed by other users. This af...

Aug 6, 2025
CVE-2025-51504
7.6

Microweber CMS 2.0 contains a stored cross-site scripting (XSS) vulnerability in the profile page's last name field. This allows attackers to inject m...

Aug 1, 2025
CVE-2025-53528
7.6

CVE-2025-53528 is a reflected cross-site scripting (XSS) vulnerability in Cadwyn's API documentation endpoint. An attacker can craft a malicious URL c...

Jul 21, 2025
CVE-2025-52902
7.6

File Browser versions prior to 2.33.7 have a stored cross-site scripting (XSS) vulnerability in the Markdown preview function. When users upload Markd...

Jun 26, 2025
CVE-2025-49262
7.6

This stored cross-site scripting (XSS) vulnerability in the Sina Extension for Elementor WordPress plugin allows attackers to inject malicious scripts...

Jun 6, 2025
CVE-2025-32794
7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient creation privileges can inject malicious JavaSc...

May 23, 2025
CVE-2025-43860
7.6

OpenEMR versions before 7.0.3.4 have a stored XSS vulnerability where authenticated users with patient editing privileges can inject malicious JavaScr...

May 23, 2025
CVE-2025-4123
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in Grafana that combines client path traversal with open redirect. Attackers can redirec...

May 22, 2025
CVE-2025-3246
7.6

A cross-site scripting vulnerability in GitHub Enterprise Server allows attackers to inject malicious scripts into math blocks using $$..$$ delimiters...

Apr 17, 2025
CVE-2025-27406
7.6

This vulnerability in Icinga Reporting allows attackers to embed arbitrary JavaScript in report templates. When previewed, this enables attackers to a...

Mar 26, 2025
CVE-2025-27404
7.6

This is a cross-site scripting (XSS) vulnerability in Icinga Web 2 that allows attackers to craft malicious URLs. When any user visits such a URL, arb...

Mar 26, 2025
CVE-2025-2610
7.6

An authenticated stored cross-site scripting (XSS) vulnerability in MagnusBilling's Alarm Module allows attackers to inject malicious scripts that exe...

Mar 21, 2025
CVE-2024-11824
7.6

A stored XSS vulnerability in langgenius/dify's chat log functionality allows attackers to inject malicious HTML tags like <input> and <form> via prom...

Mar 20, 2025
CVE-2025-24885
7.6

This vulnerability allows unprivileged users to create stored cross-site scripting (XSS) attacks on the pwn.college education platform by exploiting m...

Jan 30, 2025
CVE-2025-24018
7.6

This stored XSS vulnerability in YesWiki allows authenticated users with page/comment editing rights to inject malicious scripts via the {{attach}} co...

Jan 21, 2025
CVE-2025-24017
7.6

YesWiki versions up to 4.4.5 contain a DOM-based cross-site scripting (XSS) vulnerability in the tag search feature. When users click malicious links ...

Jan 21, 2025
CVE-2024-49053
7.6

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 Sales, which execute when viewed by other users. It affect...

Nov 26, 2024
CVE-2020-11859
7.6

CVE-2020-11859 is an improper input validation vulnerability in OpenText iManager that allows cross-site scripting (XSS) attacks. Attackers can inject...

Nov 6, 2024
CVE-2024-5429
7.6

The Logo Slider WordPress plugin before version 4.1.0 contains a stored cross-site scripting (XSS) vulnerability. Users with contributor role or highe...

Oct 17, 2024
CVE-2024-47782
7.6

CVE-2024-47782 is a cross-site scripting (XSS) vulnerability in the WikiDiscover extension for CreateWiki-managed wiki farms. The vulnerability allows...

Oct 7, 2024
CVE-2024-9198
7.6

CVE-2024-9198 is a stored cross-site scripting (XSS) vulnerability in Clibo Manager v1.1.9.1 that allows attackers to upload malicious SVG images as p...

Sep 26, 2024
CVE-2024-42346
7.6

This CVE describes a stored cross-site scripting (XSS) vulnerability in Galaxy's editor visualization endpoint. Attackers can inject malicious HTML/Ja...

Sep 20, 2024
CVE-2024-39403
7.6

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Aug 14, 2024
CVE-2024-41959
7.6

This is a cross-site scripting (XSS) vulnerability in mailcow: dockerized that allows unauthenticated attackers to inject malicious JavaScript into AP...

Aug 5, 2024
CVE-2024-35266
7.6

This is a cross-site scripting (XSS) vulnerability in Azure DevOps Server that allows attackers to inject malicious scripts into web pages viewed by o...

Jul 9, 2024
CVE-2024-2301
7.6

HP LaserJet Pro printers are vulnerable to cross-site scripting (XSS) attacks through their web management interface. This allows attackers to inject ...

May 23, 2024
CVE-2024-30047
7.6

CVE-2024-30047 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Insights that allows attackers to inject malicious scr...

May 14, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,863 CVEs classified as CWE-79, with 273 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free