CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,784
Total CVEs
252
Critical
2,320
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
934
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,784)

CVE-2024-7982
9.6

This vulnerability in the Registrations for the Events Calendar WordPress plugin allows unauthenticated attackers to inject malicious scripts into eve...

Nov 8, 2024
CVE-2024-46367
9.6

A stored cross-site scripting vulnerability in Webkul Krayin CRM 1.3.0 allows attackers to inject malicious JavaScript via the username field. When ex...

Sep 27, 2024
CVE-2024-44777
9.6

A reflected cross-site scripting vulnerability in vTiger CRM 7.4.0 allows attackers to inject malicious scripts via the tag parameter. When exploited,...

Aug 29, 2024
CVE-2024-44779
9.6

This reflected cross-site scripting (XSS) vulnerability in vTiger CRM 7.4.0 allows attackers to inject malicious scripts via the viewname parameter. W...

Aug 29, 2024
CVE-2023-6452
9.6

This stored XSS vulnerability in Forcepoint Web Security allows attackers to inject malicious JavaScript into the Transaction Viewer's user agent fiel...

Aug 22, 2024
CVE-2024-28740
9.6

A cross-site scripting (XSS) vulnerability in Koha Integrated Library System allows remote attackers to inject malicious scripts via the additional-co...

Aug 6, 2024
CVE-2024-40618
9.6

This vulnerability in Whale browser allows attackers to execute malicious JavaScript code due to improper sanitization in a built-in extension. Attack...

Jul 11, 2024
CVE-2024-23997
9.6

CVE-2024-23997 is a cross-site scripting (XSS) vulnerability in Lukas Bach yana versions ≤1.0.16 that allows attackers to inject malicious scripts v...

Jul 5, 2024
CVE-2024-35225
9.6

Jupyter Server Proxy versions 3.x before 3.2.4 and 4.x before 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the /proxy endpoin...

Jun 11, 2024
CVE-2024-3166
9.6

A Cross-Site Scripting (XSS) vulnerability in mintplex-labs/anything-llm allows attackers to execute arbitrary JavaScript code by exploiting the appli...

Jun 6, 2024
CVE-2023-51219
9.6

A deep link validation vulnerability in KakaoTalk allowed attackers to execute arbitrary JavaScript in WebViews, which could leak access tokens and en...

Jun 3, 2024
CVE-2024-35592
9.6

An arbitrary file upload vulnerability in Box-IM v2.0 allows attackers to upload malicious PDF files that can execute arbitrary code on the server. Th...

May 24, 2024
CVE-2024-34716
9.6

This is a stored cross-site scripting (XSS) vulnerability in PrestaShop that allows attackers to upload malicious files through the contact form. When...

May 14, 2024
CVE-2024-34070
9.6

Froxlor versions before 2.1.9 have a stored blind XSS vulnerability in the failed login logging feature. Unauthenticated attackers can inject maliciou...

May 14, 2024
CVE-2023-51633
9.6

This is a cross-site scripting (XSS) vulnerability in Centreon's SNMP sysName OID processing that allows remote code execution. Attackers can inject m...

May 3, 2024
CVE-2023-50231
9.6

This is a stored cross-site scripting (XSS) vulnerability in NETGEAR ProSAFE Network Management System that allows remote attackers to inject maliciou...

May 3, 2024
CVE-2023-27335
9.6

This is a cross-site scripting (XSS) vulnerability in Softing edgeAggregator client that allows remote attackers to execute arbitrary scripts. When co...

May 3, 2024
CVE-2024-4405
9.6

This is a cross-site scripting (XSS) vulnerability in Xiaomi Pro 13 smartphones that allows remote code execution. Attackers can inject malicious scri...

May 2, 2024
CVE-2024-32340
9.6

This cross-site scripting (XSS) vulnerability in WonderCMS v3.4.3 allows attackers to inject malicious scripts into the website title parameter, which...

Apr 17, 2024
CVE-2024-31650
9.6

This vulnerability allows attackers to inject malicious scripts into the Last Name parameter of Cosmetics and Beauty Product Online Store v1.0, enabli...

Apr 15, 2024
CVE-2024-22718
9.6

This is a Cross-Site Scripting (XSS) vulnerability in Form Tools 3.1.1 that allows attackers to inject malicious scripts via the client_id parameter i...

Apr 11, 2024
CVE-2024-24275
9.6

A cross-site scripting (XSS) vulnerability in Teamwire Windows desktop client versions 2.0.1 through 2.4.0 allows remote attackers to inject malicious...

Mar 5, 2024
CVE-2023-42498
9.6

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into the Language Overr...

Feb 21, 2024
CVE-2024-25147
9.6

This cross-site scripting (XSS) vulnerability in Liferay's HtmlUtil.escapeJsLink function allows attackers to inject malicious JavaScript or HTML thro...

Feb 21, 2024
CVE-2023-48974
9.6

This Cross-Site Scripting (XSS) vulnerability in Axigen WebMail allows remote attackers to inject malicious scripts via the serverName_input parameter...

Feb 8, 2024
CVE-2024-25145
9.6

This stored XSS vulnerability in Liferay's Portal Search module allows authenticated attackers to inject malicious scripts into search results when hi...

Feb 7, 2024
CVE-2023-49657
9.6

This stored cross-site scripting (XSS) vulnerability in Apache Superset allows authenticated attackers with create/update permissions to inject malici...

Jan 23, 2024
CVE-2023-48728
9.6

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo's getOpenGraph videoName functionality that allows attackers to inject malici...

Jan 10, 2024
CVE-2023-31546
9.6

This Cross-Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to inject malicious scripts through the search feature, which could l...

Dec 14, 2023
CVE-2023-47797
9.6

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal allows remote attackers to inject malicious scripts or HTML via the p_l_back...

Nov 17, 2023
CVE-2023-45136
9.6

This vulnerability allows reflected cross-site scripting (XSS) in XWiki's page creation form when document name validation is enabled. An attacker can...

Oct 25, 2023
CVE-2023-45992
9.6

This vulnerability allows remote unauthenticated attackers to execute persistent cross-site scripting (XSS) and cross-site request forgery (CSRF) atta...

Oct 19, 2023
CVE-2022-37830
9.6

CVE-2022-37830 is a cross-site scripting (XSS) vulnerability in Interway a.s WebJET CMS version 8.6.896 that allows attackers to inject malicious scri...

Oct 19, 2023
CVE-2023-42627
9.6

This vulnerability allows remote attackers to inject malicious scripts into multiple address fields in Liferay's Commerce module. When exploited, thes...

Oct 17, 2023
CVE-2023-42497
9.6

This reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into the Export for Translation page of affected ...

Oct 17, 2023
CVE-2023-38888
9.6

This is a Cross-Site Scripting (XSS) vulnerability in Dolibarr ERP CRM's REST API module that allows remote attackers to inject malicious scripts. Whe...

Sep 20, 2023
CVE-2023-39007
9.6

This vulnerability allows cross-site scripting (XSS) attacks in OPNsense firewall management interfaces. Attackers can inject malicious scripts via th...

Aug 9, 2023
CVE-2023-3526
9.6

CVE-2023-3526 is a cross-site scripting (XSS) vulnerability in PHOENIX CONTACT TC ROUTER and TC CLOUD CLIENT devices that allows unauthenticated remot...

Aug 8, 2023
CVE-2023-30319
9.6

This CVE describes a Cross-Site Scripting (XSS) vulnerability in the username field of the ChatEngine application's login servlet. Attackers can injec...

Jul 6, 2023
CVE-2023-35162
9.6

This is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious JavaScript via specially crafted URLs. ...

Jun 23, 2023
CVE-2023-1892
9.6

CVE-2023-1892 is a reflected cross-site scripting (XSS) vulnerability in Sidekiq web dashboard prior to version 7.0.8. Attackers can inject malicious ...

Apr 21, 2023
CVE-2020-21487
9.6

This CVE describes a cross-site scripting (XSS) vulnerability in Netgate pfSense's ACME package that allows attackers to inject malicious scripts via ...

Apr 4, 2023
CVE-2020-19947
9.6

CVE-2020-19947 is a cross-site scripting (XSS) vulnerability in Markdown Edit that allows remote attackers to inject malicious scripts via the edit pa...

Mar 16, 2023
CVE-2023-27898
9.6

This stored cross-site scripting (XSS) vulnerability in Jenkins allows attackers to inject malicious scripts into error messages about plugin incompat...

Mar 10, 2023
CVE-2023-27905
9.6

This stored XSS vulnerability in Jenkins update-center2 allows attackers who can provide plugins for hosting to inject malicious scripts into plugin d...

Mar 10, 2023
CVE-2022-29168
9.6

Wire secure messaging application is vulnerable to cross-site scripting (XSS) via insufficient escaping of @mentions. This allows attackers to inject ...

Jun 25, 2022
CVE-2022-32271
9.6

CVE-2022-32271 is a critical remote code execution vulnerability in Real Player's DCP:// URI handler. Attackers can exploit this by tricking users int...

Jun 3, 2022
CVE-2022-24799
9.6

This is a cross-site scripting (XSS) vulnerability in Wire's web application interface that allows attackers to inject and execute arbitrary JavaScrip...

Apr 20, 2022
CVE-2021-32157
9.6

This Cross-Site Scripting (XSS) vulnerability in Webmin 1.973 allows attackers to inject malicious scripts via the Scheduled Cron Jobs feature. When e...

Apr 11, 2022
CVE-2021-37208
9.6

This vulnerability allows attackers in a privileged position to execute cross-site scripting (XSS) attacks on affected Siemens RUGGEDCOM industrial ne...

Mar 8, 2022

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,784 CVEs classified as CWE-79, with 252 rated critical and 2,320 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free