CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,864
Total CVEs
274
Critical
2,373
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,864)

CVE-2024-32979
7.5

CVE-2024-32979 is a reflected cross-site scripting vulnerability in Nautobot's filterable object-list views. Attackers can craft malicious URLs that e...

May 1, 2024
CVE-2024-27133
7.5

CVE-2024-27133 is a cross-site scripting (XSS) vulnerability in MLflow that occurs when running recipes with untrusted datasets. Insufficient sanitiza...

Feb 23, 2024
CVE-2024-1474
7.5

This vulnerability allows attackers to inject malicious scripts into the WS_FTP Server administrative interface through user-supplied inputs. When exp...

Feb 21, 2024
CVE-2024-1647
7.5

Pyhtml2pdf version 0.0.6 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to read arbitrary local files. Attackers can...

Feb 20, 2024
CVE-2023-6123
7.5

This CVE describes an improper input neutralization vulnerability (Cross-Site Scripting) in OpenText ALM Octane versions 16.2.100 and above. Attackers...

Feb 15, 2024
CVE-2023-41815
7.5

This CVE describes a cross-site scripting (XSS) vulnerability in Pandora FMS that allows attackers to inject malicious scripts into the File Manager s...

Dec 29, 2023
CVE-2023-42478
7.5

SAP Business Objects Business Intelligence Platform contains a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to ...

Dec 12, 2023
CVE-2023-48701
7.5

This vulnerability allows attackers to upload HTML files disguised as images in Statamic CMS, bypassing MIME type validation. This affects front-end f...

Nov 21, 2023
CVE-2023-46251
7.5

This DOM-based XSS vulnerability in MyBB forum software allows attackers to execute malicious JavaScript in victims' browsers by tricking them into vi...

Nov 6, 2023
CVE-2023-41681
7.5

This is a cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox that allows attackers to inject malicious scripts via crafted HTTP request...

Oct 13, 2023
CVE-2023-41843
7.5

This cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox allows attackers to inject malicious scripts via crafted HTTP requests, which c...

Oct 13, 2023
CVE-2023-41049
7.5

This CVE describes a cross-site scripting (XSS) vulnerability in the @dcl/single-sign-on-client npm library. Improper input validation in the init fun...

Sep 1, 2023
CVE-2023-40577
7.5

This cross-site scripting (XSS) vulnerability in Prometheus Alertmanager allows attackers with POST permission to the /api/v1/alerts endpoint to injec...

Aug 25, 2023
CVE-2023-28598
7.5

Zoom for Linux clients prior to version 5.13.10 contain an HTML injection vulnerability (CWE-79) that allows malicious users to inject arbitrary HTML ...

Jun 13, 2023
CVE-2023-27378
7.5

This CVE describes multiple reflected cross-site scripting (XSS) vulnerabilities in undisclosed pages of the BIG-IP Configuration utility. Attackers c...

May 3, 2023
CVE-2022-40676
7.5

This is a cross-site scripting (XSS) vulnerability in Fortinet FortiNAC network access control solutions. Attackers can inject malicious scripts via c...

Mar 7, 2023
CVE-2022-34966
7.5

CVE-2022-34966 is an HTML injection vulnerability in OpenTeknik OSSN v6.3 LTS that allows attackers to inject malicious HTML content via the location ...

Jul 25, 2022
CVE-2022-2199
7.5

This vulnerability is a reflected cross-site scripting (XSS) flaw in the MiCODUS MV720 GPS tracker web server, allowing an attacker to inject maliciou...

Jul 20, 2022
CVE-2022-1430
7.5

This DOM-based XSS vulnerability in OctoPrint allows attackers to inject malicious scripts that execute in users' browsers when viewing manipulated co...

May 18, 2022
CVE-2021-23228
7.5

DIAEnergie versions 1.7.5 and earlier contain a reflected cross-site scripting (XSS) vulnerability in error pages that process .NET Request.QueryStrin...

Dec 22, 2021
CVE-2021-44544
7.5

DIAEnergie versions 1.7.5 and earlier contain a cross-site scripting (XSS) vulnerability in the 'name' parameter of HandlerEnergyType.ashx. This allow...

Dec 22, 2021
CVE-2021-29625
7.5

This is a cross-site scripting (XSS) vulnerability in Adminer database management software that allows attackers to inject malicious scripts into web ...

May 19, 2021
CVE-2020-35937
7.5

This stored XSS vulnerability in the Team Showcase WordPress plugin allows remote authenticated attackers to inject malicious JavaScript via AJAX requ...

Jan 1, 2021
CVE-2020-35475
7.5

This is a cross-site scripting (XSS) vulnerability in MediaWiki's user rights management interface. It allows attackers to inject malicious scripts th...

Dec 18, 2020
CVE-2025-65098
7.4

This vulnerability in Typebot allows attackers to steal stored credentials (OpenAI keys, Google Sheets tokens, SMTP passwords) from any user who previ...

Jan 22, 2026
CVE-2025-40772
7.4

A stored Cross-Site Scripting vulnerability in SiPass integrated allows attackers to inject malicious scripts that execute when other users visit affe...

Oct 14, 2025
CVE-2025-6248
7.4

A cross-site scripting vulnerability in Lenovo Browser allows attackers to execute malicious scripts in users' browsers when visiting specially crafte...

Jul 17, 2025
CVE-2025-27447
7.4

This cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript into the web application via specially crafted URLs. Whe...

Jul 3, 2025
CVE-2024-36249
7.4

This cross-site scripting (XSS) vulnerability in Sharp and Toshiba multifunction printers allows attackers to execute arbitrary scripts on the adminis...

Nov 26, 2024
CVE-2024-50441
7.4

A stored cross-site scripting (XSS) vulnerability in the Cozy Blocks WordPress plugin allows attackers to inject malicious scripts into web pages. Whe...

Oct 28, 2024
CVE-2024-47801
7.4

Sharp and Toshiba Tec multifunction printers (MFPs) have a reflected cross-site scripting vulnerability where specially crafted URLs can execute malic...

Oct 25, 2024
CVE-2024-5091
7.4

The SKT Addons for Elementor WordPress plugin has a stored cross-site scripting (XSS) vulnerability in its Age Gate and Creative Slider widgets. Authe...

Jun 8, 2024
CVE-2024-3667
7.4

The Brizy Page Builder WordPress plugin has a stored XSS vulnerability in its 'Link To' field across multiple widgets. Authenticated attackers with co...

Jun 5, 2024
CVE-2024-33306
7.4

CVE-2024-33306 is a stored cross-site scripting (XSS) vulnerability in SourceCodester Laboratory Management System 1.0 that allows attackers to inject...

May 1, 2024
CVE-2024-30920
7.4

This Cross-Site Scripting (XSS) vulnerability in DerbyNet allows remote attackers to inject malicious scripts via the render-document.php component. W...

Apr 18, 2024
CVE-2024-29154
7.4

This vulnerability allows cross-site scripting (XSS) attacks in danielmiessler fabric versions through 1.3.0 due to improper handling of innerHTML in ...

Mar 18, 2024
CVE-2024-1536
7.4

This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into pages using the ...

Mar 13, 2024
CVE-2024-1529
7.4

CMS Made Simple 2.2.14 has a cross-site scripting vulnerability in the admin user creation page that allows attackers to inject malicious JavaScript. ...

Mar 12, 2024
CVE-2020-36769
7.4

This vulnerability allows authenticated WordPress users with subscriber-level permissions or higher to inject malicious JavaScript into website pages ...

Dec 23, 2023
CVE-2020-18336
7.4

This vulnerability allows remote attackers to execute arbitrary JavaScript code in Typora's PDF export function, potentially stealing sensitive inform...

Oct 10, 2023
CVE-2023-4136
7.4

This CVE describes a reflected cross-site scripting (XSS) vulnerability in CrafterCMS Engine that allows attackers to inject malicious scripts into we...

Aug 3, 2023
CVE-2021-42080
7.4

This vulnerability allows attackers to execute reflected cross-site scripting (XSS) attacks via specially crafted URLs in OSnexus QuantaStor storage s...

Jul 10, 2023
CVE-2022-23622
7.4

This is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts via the xredirect parameter in ...

Feb 9, 2022
CVE-2021-43776
7.4

This Cross-Site Scripting (XSS) vulnerability in Backstage's auth-backend plugin allows attackers to craft malicious URLs that, when visited by users,...

Nov 26, 2021
CVE-2021-40457
7.4

CVE-2021-40457 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious s...

Oct 13, 2021
CVE-2021-32797
7.4

JupyterLab versions before 3.1.0 contain a cross-site scripting vulnerability where untrusted notebooks can execute arbitrary code when loaded. The vu...

Aug 9, 2021
CVE-2021-37633
7.4

This Cross-Site Scripting (XSS) vulnerability in Discourse allows attackers to inject malicious scripts into d-popover tooltips, potentially compromis...

Aug 9, 2021
CVE-2021-21004
7.4

This vulnerability allows attackers to inject malicious code into Phoenix Contact FL SWITCH SMCS series network switches via LLDP frames, which then e...

Jun 25, 2021
CVE-2020-35947
7.4

This vulnerability in the PageLayer WordPress plugin allows authenticated users to execute AJAX actions without proper permission checks, including mo...

Jan 1, 2021
CVE-2020-12778
7.4

This CVE describes a cross-site scripting (XSS) vulnerability in Combodo iTop where attackers can inject malicious commands due to improper input vali...

Aug 10, 2020

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,864 CVEs classified as CWE-79, with 274 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free