CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,864)
CVE-2024-32979 is a reflected cross-site scripting vulnerability in Nautobot's filterable object-list views. Attackers can craft malicious URLs that e...
May 1, 2024CVE-2024-27133 is a cross-site scripting (XSS) vulnerability in MLflow that occurs when running recipes with untrusted datasets. Insufficient sanitiza...
Feb 23, 2024This vulnerability allows attackers to inject malicious scripts into the WS_FTP Server administrative interface through user-supplied inputs. When exp...
Feb 21, 2024Pyhtml2pdf version 0.0.6 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to read arbitrary local files. Attackers can...
Feb 20, 2024This CVE describes an improper input neutralization vulnerability (Cross-Site Scripting) in OpenText ALM Octane versions 16.2.100 and above. Attackers...
Feb 15, 2024This CVE describes a cross-site scripting (XSS) vulnerability in Pandora FMS that allows attackers to inject malicious scripts into the File Manager s...
Dec 29, 2023SAP Business Objects Business Intelligence Platform contains a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to ...
Dec 12, 2023This vulnerability allows attackers to upload HTML files disguised as images in Statamic CMS, bypassing MIME type validation. This affects front-end f...
Nov 21, 2023This DOM-based XSS vulnerability in MyBB forum software allows attackers to execute malicious JavaScript in victims' browsers by tricking them into vi...
Nov 6, 2023This is a cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox that allows attackers to inject malicious scripts via crafted HTTP request...
Oct 13, 2023This cross-site scripting (XSS) vulnerability in Fortinet FortiSandbox allows attackers to inject malicious scripts via crafted HTTP requests, which c...
Oct 13, 2023This CVE describes a cross-site scripting (XSS) vulnerability in the @dcl/single-sign-on-client npm library. Improper input validation in the init fun...
Sep 1, 2023This cross-site scripting (XSS) vulnerability in Prometheus Alertmanager allows attackers with POST permission to the /api/v1/alerts endpoint to injec...
Aug 25, 2023Zoom for Linux clients prior to version 5.13.10 contain an HTML injection vulnerability (CWE-79) that allows malicious users to inject arbitrary HTML ...
Jun 13, 2023This CVE describes multiple reflected cross-site scripting (XSS) vulnerabilities in undisclosed pages of the BIG-IP Configuration utility. Attackers c...
May 3, 2023This is a cross-site scripting (XSS) vulnerability in Fortinet FortiNAC network access control solutions. Attackers can inject malicious scripts via c...
Mar 7, 2023CVE-2022-34966 is an HTML injection vulnerability in OpenTeknik OSSN v6.3 LTS that allows attackers to inject malicious HTML content via the location ...
Jul 25, 2022This vulnerability is a reflected cross-site scripting (XSS) flaw in the MiCODUS MV720 GPS tracker web server, allowing an attacker to inject maliciou...
Jul 20, 2022This DOM-based XSS vulnerability in OctoPrint allows attackers to inject malicious scripts that execute in users' browsers when viewing manipulated co...
May 18, 2022DIAEnergie versions 1.7.5 and earlier contain a reflected cross-site scripting (XSS) vulnerability in error pages that process .NET Request.QueryStrin...
Dec 22, 2021DIAEnergie versions 1.7.5 and earlier contain a cross-site scripting (XSS) vulnerability in the 'name' parameter of HandlerEnergyType.ashx. This allow...
Dec 22, 2021This is a cross-site scripting (XSS) vulnerability in Adminer database management software that allows attackers to inject malicious scripts into web ...
May 19, 2021This stored XSS vulnerability in the Team Showcase WordPress plugin allows remote authenticated attackers to inject malicious JavaScript via AJAX requ...
Jan 1, 2021This is a cross-site scripting (XSS) vulnerability in MediaWiki's user rights management interface. It allows attackers to inject malicious scripts th...
Dec 18, 2020This vulnerability in Typebot allows attackers to steal stored credentials (OpenAI keys, Google Sheets tokens, SMTP passwords) from any user who previ...
Jan 22, 2026A stored Cross-Site Scripting vulnerability in SiPass integrated allows attackers to inject malicious scripts that execute when other users visit affe...
Oct 14, 2025A cross-site scripting vulnerability in Lenovo Browser allows attackers to execute malicious scripts in users' browsers when visiting specially crafte...
Jul 17, 2025This cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript into the web application via specially crafted URLs. Whe...
Jul 3, 2025This cross-site scripting (XSS) vulnerability in Sharp and Toshiba multifunction printers allows attackers to execute arbitrary scripts on the adminis...
Nov 26, 2024A stored cross-site scripting (XSS) vulnerability in the Cozy Blocks WordPress plugin allows attackers to inject malicious scripts into web pages. Whe...
Oct 28, 2024Sharp and Toshiba Tec multifunction printers (MFPs) have a reflected cross-site scripting vulnerability where specially crafted URLs can execute malic...
Oct 25, 2024The SKT Addons for Elementor WordPress plugin has a stored cross-site scripting (XSS) vulnerability in its Age Gate and Creative Slider widgets. Authe...
Jun 8, 2024The Brizy Page Builder WordPress plugin has a stored XSS vulnerability in its 'Link To' field across multiple widgets. Authenticated attackers with co...
Jun 5, 2024CVE-2024-33306 is a stored cross-site scripting (XSS) vulnerability in SourceCodester Laboratory Management System 1.0 that allows attackers to inject...
May 1, 2024This Cross-Site Scripting (XSS) vulnerability in DerbyNet allows remote attackers to inject malicious scripts via the render-document.php component. W...
Apr 18, 2024This vulnerability allows cross-site scripting (XSS) attacks in danielmiessler fabric versions through 1.3.0 due to improper handling of innerHTML in ...
Mar 18, 2024This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into pages using the ...
Mar 13, 2024CMS Made Simple 2.2.14 has a cross-site scripting vulnerability in the admin user creation page that allows attackers to inject malicious JavaScript. ...
Mar 12, 2024This vulnerability allows authenticated WordPress users with subscriber-level permissions or higher to inject malicious JavaScript into website pages ...
Dec 23, 2023This vulnerability allows remote attackers to execute arbitrary JavaScript code in Typora's PDF export function, potentially stealing sensitive inform...
Oct 10, 2023This CVE describes a reflected cross-site scripting (XSS) vulnerability in CrafterCMS Engine that allows attackers to inject malicious scripts into we...
Aug 3, 2023This vulnerability allows attackers to execute reflected cross-site scripting (XSS) attacks via specially crafted URLs in OSnexus QuantaStor storage s...
Jul 10, 2023This is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts via the xredirect parameter in ...
Feb 9, 2022This Cross-Site Scripting (XSS) vulnerability in Backstage's auth-backend plugin allows attackers to craft malicious URLs that, when visited by users,...
Nov 26, 2021CVE-2021-40457 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious s...
Oct 13, 2021JupyterLab versions before 3.1.0 contain a cross-site scripting vulnerability where untrusted notebooks can execute arbitrary code when loaded. The vu...
Aug 9, 2021This Cross-Site Scripting (XSS) vulnerability in Discourse allows attackers to inject malicious scripts into d-popover tooltips, potentially compromis...
Aug 9, 2021This vulnerability allows attackers to inject malicious code into Phoenix Contact FL SWITCH SMCS series network switches via LLDP frames, which then e...
Jun 25, 2021This vulnerability in the PageLayer WordPress plugin allows authenticated users to execute AJAX actions without proper permission checks, including mo...
Jan 1, 2021This CVE describes a cross-site scripting (XSS) vulnerability in Combodo iTop where attackers can inject malicious commands due to improper input vali...
Aug 10, 2020About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,864 CVEs classified as CWE-79, with 274 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free