CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,863
Total CVEs
273
Critical
2,373
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,863)

CVE-2024-4336
7.6

Adive Framework 2.0.8 has a persistent Cross-Site Scripting (XSS) vulnerability in the admin tables add endpoint due to insufficient input encoding. T...

Apr 30, 2024
CVE-2024-29504
7.6

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Summernote versions 0.8.18 and earlier. An attacker can inject malicious JavaScript v...

Apr 10, 2024
CVE-2024-21419
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises deployments that allows attackers to inject malicious scripts...

Mar 12, 2024
CVE-2024-21393
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...

Feb 13, 2024
CVE-2024-21389
7.6

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victim...

Feb 13, 2024
CVE-2024-21328
7.6

CVE-2024-21328 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Sales that allows attackers to inject malicious scripts into we...

Feb 13, 2024
CVE-2024-22130
7.6

This CVE describes a cross-site scripting (XSS) vulnerability in SAP CRM WebClient UI's print preview feature. Attackers with low-privilege access can...

Feb 13, 2024
CVE-2024-21637
7.6

Authentik is vulnerable to reflected Cross-Site Scripting (XSS) via JavaScript-URIs in OpenID Connect flows when using response_mode=form_post. This a...

Jan 11, 2024
CVE-2023-6366
7.6

This stored XSS vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into the Alert Center. When users interact with the craf...

Dec 14, 2023
CVE-2023-6364
7.6

A stored cross-site scripting (XSS) vulnerability in WhatsUp Gold allows attackers to inject malicious JavaScript into dashboard components. When user...

Dec 14, 2023
CVE-2023-36410
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...

Nov 14, 2023
CVE-2023-36886
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pa...

Sep 12, 2023
CVE-2023-36800
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Finance and Operations that allows attackers to inject malicious scripts ...

Sep 12, 2023
CVE-2023-39437
7.6

CVE-2023-39437 is a cross-site scripting (XSS) vulnerability in SAP Business One version 10.0 that allows attackers to inject malicious scripts into w...

Aug 8, 2023
CVE-2022-43376
7.6

This cross-site scripting (XSS) vulnerability in NetBotz 4 environmental monitoring devices allows attackers to inject malicious scripts into web page...

Apr 18, 2023
CVE-2023-28309
7.6

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victim...

Apr 11, 2023
CVE-2023-27489
7.6

Kiwi TCMS versions before 12.1 are vulnerable to cross-site scripting (XSS) via malicious SVG file uploads. When users upload SVG files containing Jav...

Mar 29, 2023
CVE-2022-0565
7.6

This is a cross-site scripting (XSS) vulnerability in Pimcore's web interface that allows attackers to inject malicious scripts into web pages viewed ...

Feb 14, 2022
CVE-2022-21932
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious scripts int...

Jan 11, 2022
CVE-2022-21649
7.6

CVE-2022-21649 is a stored cross-site scripting (XSS) vulnerability in Convos chat software where URLs starting with 'https://' in chat messages are i...

Jan 4, 2022
CVE-2021-42360
7.6

This vulnerability allows Contributor-level WordPress users to import malicious blocks containing JavaScript onto any page built with Elementor, overw...

Nov 17, 2021
CVE-2021-41372
7.6

This vulnerability allows attackers to upload malicious Power BI template files containing HTML with scripts. When victims access these HTML files, th...

Nov 10, 2021
CVE-2021-34354
7.6

This cross-site scripting (XSS) vulnerability in QNAP Photo Station allows remote attackers to inject malicious JavaScript code into web pages viewed ...

Oct 1, 2021
CVE-2021-34356
7.6

This cross-site scripting (XSS) vulnerability in QNAP Photo Station allows remote attackers to inject malicious JavaScript code into web pages viewed ...

Oct 1, 2021
CVE-2021-39201
7.6

This vulnerability allows authenticated low-privileged WordPress users (like contributors or authors) to execute cross-site scripting (XSS) attacks in...

Sep 9, 2021
CVE-2021-32808
7.6

CVE-2021-32808 is a cross-site scripting (XSS) vulnerability in CKEditor 4 that allows attackers to execute arbitrary JavaScript code by exploiting a ...

Aug 12, 2021
CVE-2021-29489
7.6

CVE-2021-29489 is a cross-site scripting (XSS) vulnerability in Highcharts JS versions 8 and earlier. It allows attackers to inject malicious scripts ...

May 5, 2021
CVE-2021-21383
7.6

Wiki.js versions before 2.5.191 are vulnerable to stored cross-site scripting (XSS) through mustache expressions in code blocks. Malicious users can c...

Mar 18, 2021
CVE-2021-21260
7.6

This stored cross-site scripting (XSS) vulnerability in Online Invoicing System version 4.0 allows attackers to inject malicious scripts into item des...

Jan 22, 2021
CVE-2020-26239
7.6

This CVE describes a DOM-based cross-site scripting (XSS) vulnerability in the Scratch Addons browser extension. Attackers could exploit this by trick...

Nov 23, 2020
CVE-2020-16872
7.6

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scr...

Sep 11, 2020
CVE-2020-14610
7.6

This CVE-2020-14610 is a cross-site scripting (XSS) vulnerability in Oracle Applications Framework's file upload component. It allows authenticated at...

Jul 15, 2020
CVE-2025-59467
7.5

This Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin allows attackers to execute malicious scripts in administrato...

Jan 5, 2026
CVE-2024-58304
7.5

SPA-CART CMS 1.9.0.3 has a stored cross-site scripting (XSS) vulnerability in the product description field, allowing authenticated administrators to ...

Dec 11, 2025
CVE-2025-24853
7.5

CVE-2025-24853 is a cross-site scripting (XSS) vulnerability in Apache JSPWiki that allows attackers to inject malicious JavaScript via wiki markup sy...

Jul 31, 2025
CVE-2025-22243
7.5

VMware NSX Manager UI has a stored XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This affe...

Jun 4, 2025
CVE-2024-26006
7.5

This vulnerability allows remote unauthenticated attackers to perform cross-site scripting (XSS) attacks through the SSL VPN web interface in affected...

Mar 14, 2025
CVE-2025-26907
7.5

This stored cross-site scripting (XSS) vulnerability in the Estatik Mortgage Calculator WordPress plugin allows attackers to inject malicious scripts ...

Feb 25, 2025
CVE-2024-40748
7.5

This Cross-Site Scripting (XSS) vulnerability in Joomla allows attackers to inject malicious scripts into menu list ID attributes. When exploited, it ...

Jan 7, 2025
CVE-2024-47924
7.5

This CVE describes a cross-site scripting (XSS) vulnerability in the Boa web server that allows attackers to inject malicious scripts into web pages. ...

Dec 30, 2024
CVE-2024-56527
7.5

This vulnerability in TCPDF allows cross-site scripting (XSS) attacks through unescaped error messages. Attackers can inject malicious scripts that ex...

Dec 27, 2024
CVE-2024-56519
7.5

This vulnerability in TCPPDF allows cross-site scripting (XSS) attacks via malicious SVG files. Attackers can inject JavaScript through the font-famil...

Dec 27, 2024
CVE-2024-48536
7.5

This vulnerability allows attackers to bypass access controls in eSoft Planner 3.24.08271-USA by sending specially crafted web requests, enabling unau...

Nov 20, 2024
CVE-2024-52598
7.5

CVE-2024-52598 is a Server-Side Request Forgery (SSRF) vulnerability in 2FAuth version 5.4.1 that allows attackers to make the application send HTTP r...

Nov 20, 2024
CVE-2024-45254
7.5

This CVE describes a cross-site scripting (XSS) vulnerability in VaeMendis software that allows attackers to inject malicious scripts into web pages v...

Nov 14, 2024
CVE-2020-11926
7.5

CVE-2020-11926 allows unauthenticated attackers to retrieve device credentials and Wi-Fi network information from Luvion Grand Elite 3 Connect devices...

Nov 7, 2024
CVE-2024-44080
7.5

This vulnerability in Jitsi Meet allows attackers to make clients load GIFs from arbitrary URLs by sending specially crafted messages. This affects al...

Oct 29, 2024
CVE-2024-47527
7.5

This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript through device names in the Device Dependencies fe...

Oct 1, 2024
CVE-2024-9394
7.5

This vulnerability allows attackers to execute arbitrary JavaScript in the privileged devtools origin via specially crafted multipart responses, enabl...

Oct 1, 2024
CVE-2024-32979
7.5

CVE-2024-32979 is a reflected cross-site scripting vulnerability in Nautobot's filterable object-list views. Attackers can craft malicious URLs that e...

May 1, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,863 CVEs classified as CWE-79, with 273 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free