CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,864
Total CVEs
274
Critical
2,373
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,864)

CVE-2020-4041
7.4

This stored XSS vulnerability in Bolt CMS allows attackers to inject malicious JavaScript into uploaded filenames after initial upload by renaming fil...

Jun 8, 2020
CVE-2020-4038
7.4

CVE-2020-4038 is a severe cross-site scripting (XSS) vulnerability in GraphQL Playground's HTML rendering component. It allows attackers to inject mal...

Jun 8, 2020
CVE-2026-29082
7.3

This vulnerability allows attackers to inject malicious HTML/JavaScript into Kestra's execution-file preview feature, leading to cross-site scripting ...

Mar 6, 2026
CVE-2026-26276
7.3

This CVE describes a DOM-based cross-site scripting (XSS) vulnerability in Gogs self-hosted Git service. Attackers can inject malicious JavaScript int...

Mar 5, 2026
CVE-2026-25733
7.3

Rucio versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting vulnerability in the WebUI's Custom Rules function. This allows ...

Feb 25, 2026
CVE-2026-26192
7.3

This stored cross-site scripting (XSS) vulnerability in Open WebUI allows attackers to inject malicious HTML into chat history metadata, which gets ex...

Feb 19, 2026
CVE-2025-14560
7.3

This vulnerability in GitLab allows an authenticated attacker to inject malicious content into the vulnerability code flow, potentially performing una...

Feb 11, 2026
CVE-2026-24045
7.3

Docmost versions before 0.25.0 have a stored XSS vulnerability in public share pages where page titles aren't properly HTML-escaped before insertion i...

Feb 10, 2026
CVE-2026-24672
7.3

Authenticated students in Open eClass platform can inject malicious JavaScript into user profile fields, which executes when other users view those pr...

Feb 3, 2026
CVE-2025-67849
7.3

This cross-site scripting vulnerability in Moodle allows attackers to inject malicious scripts through AI prompt responses. When users view compromise...

Feb 3, 2026
CVE-2025-67850
7.3

This Cross-Site Scripting (XSS) vulnerability in Moodle allows attackers to inject malicious JavaScript code into arithmetic expression fields in the ...

Feb 3, 2026
CVE-2026-25156
7.3

HotCRP conference review software versions from October 2025 through January 2026 incorrectly delivered all document types with inline Content-Disposi...

Jan 30, 2026
CVE-2025-61914
7.3

This stored XSS vulnerability in n8n allows attackers with workflow creation permissions to execute arbitrary JavaScript in the n8n editor interface. ...

Dec 26, 2025
CVE-2025-13183
7.3

This stored cross-site scripting (XSS) vulnerability in Hotech Software's Otello allows attackers to inject malicious scripts into web pages that are ...

Dec 23, 2025
CVE-2025-66561
7.3

SysReptor versions before 2025.102 have a stored XSS vulnerability where authenticated users can upload malicious JavaScript files through the web UI....

Dec 4, 2025
CVE-2025-11962
7.3

This stored XSS vulnerability in DivvyDrive's Digital Corporate Warehouse allows attackers to inject malicious scripts into web pages that persist and...

Nov 12, 2025
CVE-2025-7430
7.3

This stored cross-site scripting (XSS) vulnerability in ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into the Fold...

Nov 11, 2025
CVE-2025-7632
7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below contain a stored cross-site scripting (XSS) vulnerability in the Public Folders r...

Nov 11, 2025
CVE-2025-7633
7.3

This stored cross-site scripting (XSS) vulnerability in ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into custom r...

Nov 11, 2025
CVE-2025-7429
7.3

ManageEngine Exchange Reporter Plus versions 5723 and below contain a stored cross-site scripting (XSS) vulnerability in the 'Mails Deleted or Moved' ...

Nov 11, 2025
CVE-2025-63441
7.3

Open Source Social Network (OSSN) 8.6 contains a reflected cross-site scripting vulnerability in the administrator friends endpoint. Attackers can inj...

Nov 3, 2025
CVE-2025-49552
7.3

Adobe Connect versions 12.9 and earlier contain a DOM-based XSS vulnerability that allows high-privileged attackers to execute malicious scripts in vi...

Oct 14, 2025
CVE-2025-11189
7.3

The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability in the login-url parameter that allows attackers to execute ar...

Oct 10, 2025
CVE-2025-60967
7.3

This Cross-Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server allows attackers to inject malicious scripts into ...

Oct 6, 2025
CVE-2025-57424
7.3

A stored XSS vulnerability in MyCourts v3 allows attackers to inject malicious JavaScript into user profiles. When other users view these profiles, th...

Sep 29, 2025
CVE-2025-55888
7.3

This Cross-Site Scripting (XSS) vulnerability in ARD's Ajax transaction manager allows attackers to inject malicious JavaScript into the accountName f...

Sep 22, 2025
CVE-2025-55618
7.3

This CVE describes a cross-site scripting (XSS) vulnerability in the Hyundai Navigation App where an attacker can inject HTML payloads into the profil...

Aug 27, 2025
CVE-2025-48920
7.3

This CVE describes a cross-site scripting (XSS) vulnerability in the Drupal etracker module that allows attackers to inject malicious scripts into web...

Jun 13, 2025
CVE-2025-25035
7.3

This Cross-Site Scripting (XSS) vulnerability in Jalios JPlatform allows attackers to inject malicious scripts into web pages, which execute in victim...

Mar 21, 2025
CVE-2025-25823
7.3

This cross-site scripting vulnerability in Emlog Pro v2.5.4 allows attackers to inject malicious scripts into article headers via the admin interface....

Feb 26, 2025
CVE-2025-27108
7.3

This vulnerability allows attackers to execute arbitrary JavaScript in victims' browsers through Cross-site Scripting (XSS) in dom-expressions and sol...

Feb 21, 2025
CVE-2025-27109
7.3

This vulnerability in solid-js allows user input to be rendered as HTML when placed directly inside JSX fragments, enabling cross-site scripting (XSS)...

Feb 21, 2025
CVE-2025-24372
7.3

CVE-2025-24372 is a cross-site scripting (XSS) vulnerability in CKAN data management systems that allows authenticated users to upload malicious files...

Feb 5, 2025
CVE-2023-23354
7.3

This cross-site scripting (XSS) vulnerability in QNAP's QuLog Center allows remote attackers with user access to inject malicious scripts that could b...

Dec 19, 2024
CVE-2024-5125
7.3

This vulnerability in lollms-webui version 9.6 allows attackers to upload malicious SVG files containing JavaScript code that executes when rendered, ...

Nov 14, 2024
CVE-2024-47610
7.3

This is a stored cross-site scripting (XSS) vulnerability in InvenTree inventory management system. Registered users can inject malicious JavaScript i...

Oct 7, 2024
CVE-2024-43362
7.3

This stored XSS vulnerability in Cacti allows authenticated users with external link creation privileges to inject malicious scripts into web pages. W...

Oct 7, 2024
CVE-2024-40509
7.3

This Cross-Site Scripting (XSS) vulnerability in openPetra allows attackers to inject malicious scripts via the serverMFinDev.asmx function, potential...

Sep 27, 2024
CVE-2024-40511
7.3

This Cross-Site Scripting (XSS) vulnerability in openPetra v.2023.02 allows remote attackers to inject malicious scripts via the serverMServerAdmin.as...

Sep 27, 2024
CVE-2024-40506
7.3

This Cross-Site Scripting (XSS) vulnerability in openPetra allows attackers to inject malicious scripts into the serverMHospitality.asmx function, pot...

Sep 26, 2024
CVE-2024-40508
7.3

This Cross-Site Scripting (XSS) vulnerability in openPetra's serverMConference.asmx function allows attackers to inject malicious scripts into web pag...

Sep 26, 2024
CVE-2021-27917
7.3

This stored cross-site scripting (XSS) vulnerability in Mautic allows attackers to inject malicious scripts into contact tracking and page hits report...

Sep 18, 2024
CVE-2024-45799
7.3

CVE-2024-45799 is a cross-site scripting (XSS) vulnerability in FluxCP that allows attackers to inject malicious JavaScript via shop names and vendor/...

Sep 16, 2024
CVE-2024-40626
7.3

This is a stored cross-site scripting (XSS) vulnerability in Outline's document editor that allows authenticated users to inject malicious JavaScript ...

Jul 16, 2024
CVE-2024-34089
7.3

A stored cross-site scripting (XSS) vulnerability in Archer Platform 6 allows authenticated attackers to inject malicious scripts into application dat...

May 6, 2024
CVE-2024-34091
7.3

A stored cross-site scripting (XSS) vulnerability in Archer Platform 6 allows authenticated attackers to inject malicious HTML/JavaScript into the app...

May 6, 2024
CVE-2024-33338
7.3

This is a Cross-Site Scripting (XSS) vulnerability in jizhicms v2.5.4 that allows remote attackers to inject malicious scripts via crafted article pub...

Apr 29, 2024
CVE-2024-32391
7.3

This CVE describes a Cross-Site Scripting (XSS) vulnerability in MacCMS v.10 version 2024.1000.3000 that allows remote attackers to inject malicious s...

Apr 19, 2024
CVE-2024-2864
7.3

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Youzify - Buddypress Moderation WordPress plugin, pote...

Mar 25, 2024
CVE-2024-26313
7.3

Archer Platform 6.x contains a stored cross-site scripting (XSS) vulnerability that allows authenticated malicious users to inject and store malicious...

Mar 8, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,864 CVEs classified as CWE-79, with 274 rated critical and 2,373 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free