CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,863)
Adive Framework 2.0.8 has a persistent Cross-Site Scripting (XSS) vulnerability in the admin tables add endpoint due to insufficient input encoding. T...
Apr 30, 2024This CVE describes a Cross-Site Scripting (XSS) vulnerability in Summernote versions 0.8.18 and earlier. An attacker can inject malicious JavaScript v...
Apr 10, 2024This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises deployments that allows attackers to inject malicious scripts...
Mar 12, 2024This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...
Feb 13, 2024This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victim...
Feb 13, 2024CVE-2024-21328 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Sales that allows attackers to inject malicious scripts into we...
Feb 13, 2024This CVE describes a cross-site scripting (XSS) vulnerability in SAP CRM WebClient UI's print preview feature. Attackers with low-privilege access can...
Feb 13, 2024Authentik is vulnerable to reflected Cross-Site Scripting (XSS) via JavaScript-URIs in OpenID Connect flows when using response_mode=form_post. This a...
Jan 11, 2024This stored XSS vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into the Alert Center. When users interact with the craf...
Dec 14, 2023A stored cross-site scripting (XSS) vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into dashboard components. When user...
Dec 14, 2023This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...
Nov 14, 2023This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...
Sep 12, 2023This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Finance and Operations that allows attackers to inject malicious scripts ...
Sep 12, 2023CVE-2023-39437 is a cross-site scripting (XSS) vulnerability in SAP Business One version 10.0 that allows attackers to inject malicious scripts into w...
Aug 8, 2023This cross-site scripting (XSS) vulnerability in NetBotz 4 environmental monitoring devices allows attackers to inject malicious scripts into web page...
Apr 18, 2023This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victim...
Apr 11, 2023Kiwi TCMS versions before 12.1 are vulnerable to cross-site scripting (XSS) via malicious SVG file uploads. When users upload SVG files containing Jav...
Mar 29, 2023This is a cross-site scripting (XSS) vulnerability in Pimcore's web interface that allows attackers to inject malicious scripts into web pages viewed ...
Feb 14, 2022This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious scripts int...
Jan 11, 2022CVE-2022-21649 is a stored cross-site scripting (XSS) vulnerability in Convos chat software where URLs starting with 'https://' in chat messages are i...
Jan 4, 2022This vulnerability allows Contributor-level WordPress users to import malicious blocks containing JavaScript onto any page built with Elementor, overw...
Nov 17, 2021This vulnerability allows attackers to upload malicious Power BI template files containing HTML with scripts. When victims access these HTML files, th...
Nov 10, 2021This cross-site scripting (XSS) vulnerability in QNAP Photo Station allows remote attackers to inject malicious JavaScript code into web pages viewed ...
Oct 1, 2021This cross-site scripting (XSS) vulnerability in QNAP Photo Station allows remote attackers to inject malicious JavaScript code into web pages viewed ...
Oct 1, 2021This vulnerability allows authenticated low-privileged WordPress users (like contributors or authors) to execute cross-site scripting (XSS) attacks in...
Sep 9, 2021CVE-2021-32808 is a cross-site scripting (XSS) vulnerability in CKEditor 4 that allows attackers to execute arbitrary JavaScript code by exploiting a ...
Aug 12, 2021CVE-2021-29489 is a cross-site scripting (XSS) vulnerability in Highcharts JS versions 8 and earlier. It allows attackers to inject malicious scripts ...
May 5, 2021Wiki.js versions before 2.5.191 are vulnerable to stored cross-site scripting (XSS) through mustache expressions in code blocks. Malicious users can c...
Mar 18, 2021This stored cross-site scripting (XSS) vulnerability in Online Invoicing System version 4.0 allows attackers to inject malicious scripts into item des...
Jan 22, 2021This CVE describes a DOM-based cross-site scripting (XSS) vulnerability in the Scratch Addons browser extension. Attackers could exploit this by trick...
Nov 23, 2020This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scr...
Sep 11, 2020This CVE-2020-14610 is a cross-site scripting (XSS) vulnerability in Oracle Applications Framework's file upload component. It allows authenticated at...
Jul 15, 2020This Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin allows attackers to execute malicious scripts in administrato...
Jan 5, 2026SPA-CART CMS 1.9.0.3 has a stored cross-site scripting (XSS) vulnerability in the product description field, allowing authenticated administrators to ...
Dec 11, 2025CVE-2025-24853 is a cross-site scripting (XSS) vulnerability in Apache JSPWiki that allows attackers to inject malicious JavaScript via wiki markup sy...
Jul 31, 2025VMware NSX Manager UI has a stored XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This affe...
Jun 4, 2025This vulnerability allows remote unauthenticated attackers to perform cross-site scripting (XSS) attacks through the SSL VPN web interface in affected...
Mar 14, 2025This stored cross-site scripting (XSS) vulnerability in the Estatik Mortgage Calculator WordPress plugin allows attackers to inject malicious scripts ...
Feb 25, 2025This Cross-Site Scripting (XSS) vulnerability in Joomla allows attackers to inject malicious scripts into menu list ID attributes. When exploited, it ...
Jan 7, 2025This CVE describes a cross-site scripting (XSS) vulnerability in the Boa web server that allows attackers to inject malicious scripts into web pages. ...
Dec 30, 2024This vulnerability in TCPDF allows cross-site scripting (XSS) attacks through unescaped error messages. Attackers can inject malicious scripts that ex...
Dec 27, 2024This vulnerability in TCPPDF allows cross-site scripting (XSS) attacks via malicious SVG files. Attackers can inject JavaScript through the font-famil...
Dec 27, 2024This vulnerability allows attackers to bypass access controls in eSoft Planner 3.24.08271-USA by sending specially crafted web requests, enabling unau...
Nov 20, 2024CVE-2024-52598 is a Server-Side Request Forgery (SSRF) vulnerability in 2FAuth version 5.4.1 that allows attackers to make the application send HTTP r...
Nov 20, 2024This CVE describes a cross-site scripting (XSS) vulnerability in VaeMendis software that allows attackers to inject malicious scripts into web pages v...
Nov 14, 2024CVE-2020-11926 allows unauthenticated attackers to retrieve device credentials and Wi-Fi network information from Luvion Grand Elite 3 Connect devices...
Nov 7, 2024This vulnerability in Jitsi Meet allows attackers to make clients load GIFs from arbitrary URLs by sending specially crafted messages. This affects al...
Oct 29, 2024This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript through device names in the Device Dependencies fe...
Oct 1, 2024This vulnerability allows attackers to execute arbitrary JavaScript in the privileged devtools origin via specially crafted multipart responses, enabl...
Oct 1, 2024CVE-2024-32979 is a reflected cross-site scripting vulnerability in Nautobot's filterable object-list views. Attackers can craft malicious URLs that e...
May 1, 2024About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,863 CVEs classified as CWE-79, with 273 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free