CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,867)
This CVE describes a Cross-Site Scripting (XSS) vulnerability in MacCMS v.10 version 2024.1000.3000 that allows remote attackers to inject malicious s...
Apr 19, 2024This vulnerability allows attackers to inject malicious scripts into web pages generated by the Youzify - Buddypress Moderation WordPress plugin, pote...
Mar 25, 2024Archer Platform 6.x contains a stored cross-site scripting (XSS) vulnerability that allows authenticated malicious users to inject and store malicious...
Mar 8, 2024This stored cross-site scripting (XSS) vulnerability in Schoolbox's news functionality allows authenticated attackers to inject malicious scripts that...
Mar 7, 2024This stored cross-site scripting (XSS) vulnerability in Schoolbox's calendar functionality allows authenticated attackers to inject malicious scripts ...
Mar 7, 2024A stored cross-site scripting (XSS) vulnerability in Avo's key_value field allows attackers to inject malicious JavaScript that executes in victims' b...
Jan 16, 2024This is a stored cross-site scripting (XSS) vulnerability in M-Files Classic Web that allows attackers to inject malicious scripts into HTML documents...
Oct 20, 2023CVE-2023-33130 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web...
Jun 14, 2023This CVE describes a stored Cross-Site Scripting (XSS) vulnerability in the Avo Ruby on Rails admin panel framework. Attackers with form edit privileg...
Jun 5, 2023This vulnerability allows attackers to upload malicious SVG files to Mattermost Boards and share them via direct links. When users view these SVG file...
Mar 31, 2023Grafana has a stored cross-site scripting (XSS) vulnerability in the trace view visualization that allows attackers with Editor role to inject malicio...
Mar 1, 2023This CVE describes a reflected cross-site scripting (XSS) vulnerability in TIBCO BusinessConnect's UI component. An attacker with low privileges and n...
Feb 22, 2023CVE-2020-28455 is a cross-site scripting (XSS) vulnerability in the markdown-it-toc npm package. It allows attackers to inject malicious scripts into ...
Jul 25, 2022Grafana versions 8.x and 9.x before specific patched releases are vulnerable to stored cross-site scripting (XSS) in the Unified Alerting feature. An ...
Jul 15, 2022This vulnerability allows attackers to inject malicious JavaScript into Markdown content in JetBrains YouTrack's Classic UI. When exploited, it enable...
Apr 5, 2022This CVE describes a stored cross-site scripting (XSS) vulnerability in Kirby CMS's image block functionality. Authenticated attackers can inject mali...
Nov 16, 2021CVE-2021-41175 is a cross-site scripting (XSS) vulnerability in Pi-hole's web interface that allows attackers to inject malicious scripts when adding ...
Oct 26, 2021This is a privilege escalation vulnerability in Apache CouchDB where a malicious user with document creation permissions can attach HTML files contain...
Oct 14, 2021CVE-2021-37695 is a cross-site scripting (XSS) vulnerability in CKEditor 4's Fake Objects plugin that allows attackers to inject malicious HTML that c...
Aug 13, 2021This vulnerability in @scullyio/scully allows cross-site scripting (XSS) attacks through improper serialization of transfer state data. Attackers can ...
Jan 14, 2021This vulnerability allows attackers to inject malicious scripts into the S-Cart admin panel, which could execute in administrators' browsers. It affec...
Dec 15, 2020baserCMS versions 4.0.0 through 4.4.0 contain a cross-site scripting vulnerability in management interface components. Attackers with administrative a...
Oct 30, 2020baserCMS 4.3.6 and earlier contains a cross-site scripting (XSS) vulnerability in toolbar.php that allows authenticated administrators to execute arbi...
Aug 28, 2020This cross-site scripting (XSS) vulnerability in GitLab allows attackers to inject malicious scripts into milestone titles, which then execute in vict...
Aug 13, 2020This CVE describes a cross-site scripting (XSS) vulnerability in the RubyGem sanitize library. When using the 'relaxed' configuration or custom config...
Jun 16, 2020The WP App Bar WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into plugin settings....
Mar 7, 2026The Fluent Forms Pro WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into draft form...
Mar 5, 2026The WPBookit WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into w...
Mar 4, 2026Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the schedule endpoint. Attackers can inject malicious JavaScript vi...
Feb 19, 2026CVE-2019-25422 is a cross-site scripting vulnerability in Comodo Dome Firewall that allows attackers to inject malicious JavaScript through the vpnfw ...
Feb 19, 2026Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the license activation endpoint. Attackers can inject malicious Jav...
Feb 19, 2026This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wpcr3_fname' parameter in the WP Customer Reviews WordPress p...
Feb 19, 2026MajorDoMo contains an unauthenticated stored XSS vulnerability that allows attackers to inject malicious JavaScript into property values. When adminis...
Feb 18, 2026The Rent Fetch WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in the 'keyword' parameter that allows unauthenticated atta...
Feb 18, 2026The RSS Aggregator WordPress plugin is vulnerable to reflected cross-site scripting (XSS) via the 'template' parameter. Unauthenticated attackers can ...
Feb 17, 2026This stored XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript through modem.cgi POST parameters. When users acce...
Feb 16, 2026This stored and reflected XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript via the urlfilter.cgi endpoint. When...
Feb 16, 2026This cross-site scripting (XSS) vulnerability in SmarterMail allows attackers to inject malicious scripts via MAPI requests. It affects organizations ...
Feb 16, 2026The Super Page Cache WordPress plugin has a stored cross-site scripting vulnerability in its Activity Log feature. Unauthenticated attackers can injec...
Feb 14, 2026This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in victims' browsers via the 'sscf_name' parameter in the Super Si...
Feb 14, 2026The PixelYourSite WordPress plugin is vulnerable to stored cross-site scripting (XSS) via insufficient input sanitization in the 'pysTrafficSource' an...
Feb 13, 2026The Secure Copy Content Protection and Content Locking WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'X-Forwarded-For' H...
Feb 12, 2026This stored XSS vulnerability in the Customer Reviews for WooCommerce WordPress plugin allows attackers to inject malicious scripts into web pages via...
Feb 12, 2026The iONE360 configurator WordPress plugin has a stored XSS vulnerability in its contact form parameters that allows unauthenticated attackers to injec...
Feb 11, 2026The Name Directory WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via public submis...
Feb 10, 2026This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scripts into customer profile fie...
Feb 3, 2026This stored XSS vulnerability in the Sell BTC WordPress plugin allows unauthenticated attackers to inject malicious scripts into order records. When a...
Jan 31, 2026PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of change_params.php. Attackers can inject malicious...
Jan 23, 2026PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' field of the purchase page. Attacker...
Jan 23, 2026This stored cross-site scripting vulnerability in VestaCP allows attackers to inject malicious scripts into the IP interface configuration. When admin...
Jan 21, 2026About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,867 CVEs classified as CWE-79, with 274 rated critical and 2,376 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free