CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,867
Total CVEs
274
Critical
2,376
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,867)

CVE-2024-32391
7.3

This CVE describes a Cross-Site Scripting (XSS) vulnerability in MacCMS v.10 version 2024.1000.3000 that allows remote attackers to inject malicious s...

Apr 19, 2024
CVE-2024-2864
7.3

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Youzify - Buddypress Moderation WordPress plugin, pote...

Mar 25, 2024
CVE-2024-26313
7.3

Archer Platform 6.x contains a stored cross-site scripting (XSS) vulnerability that allows authenticated malicious users to inject and store malicious...

Mar 8, 2024
CVE-2024-28095
7.3

This stored cross-site scripting (XSS) vulnerability in Schoolbox's news functionality allows authenticated attackers to inject malicious scripts that...

Mar 7, 2024
CVE-2024-28097
7.3

This stored cross-site scripting (XSS) vulnerability in Schoolbox's calendar functionality allows authenticated attackers to inject malicious scripts ...

Mar 7, 2024
CVE-2024-22191
7.3

A stored cross-site scripting (XSS) vulnerability in Avo's key_value field allows attackers to inject malicious JavaScript that executes in victims' b...

Jan 16, 2024
CVE-2023-2325
7.3

This is a stored cross-site scripting (XSS) vulnerability in M-Files Classic Web that allows attackers to inject malicious scripts into HTML documents...

Oct 20, 2023
CVE-2023-33130
7.3

CVE-2023-33130 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web...

Jun 14, 2023
CVE-2023-34103
7.3

This CVE describes a stored Cross-Site Scripting (XSS) vulnerability in the Avo Ruby on Rails admin panel framework. Attackers with form edit privileg...

Jun 5, 2023
CVE-2023-1776
7.3

This vulnerability allows attackers to upload malicious SVG files to Mattermost Boards and share them via direct links. When users view these SVG file...

Mar 31, 2023
CVE-2023-0594
7.3

Grafana has a stored cross-site scripting (XSS) vulnerability in the trace view visualization that allows attackers with Editor role to inject malicio...

Mar 1, 2023
CVE-2023-26214
7.3

This CVE describes a reflected cross-site scripting (XSS) vulnerability in TIBCO BusinessConnect's UI component. An attacker with low privileges and n...

Feb 22, 2023
CVE-2020-28455
7.3

CVE-2020-28455 is a cross-site scripting (XSS) vulnerability in the markdown-it-toc npm package. It allows attackers to inject malicious scripts into ...

Jul 25, 2022
CVE-2022-31097
7.3

Grafana versions 8.x and 9.x before specific patched releases are vulnerable to stored cross-site scripting (XSS) in the Unified Alerting feature. An ...

Jul 15, 2022
CVE-2022-28650
7.3

This vulnerability allows attackers to inject malicious JavaScript into Markdown content in JetBrains YouTrack's Classic UI. When exploited, it enable...

Apr 5, 2022
CVE-2021-41258
7.3

This CVE describes a stored cross-site scripting (XSS) vulnerability in Kirby CMS's image block functionality. Authenticated attackers can inject mali...

Nov 16, 2021
CVE-2021-41175
7.3

CVE-2021-41175 is a cross-site scripting (XSS) vulnerability in Pi-hole's web interface that allows attackers to inject malicious scripts when adding ...

Oct 26, 2021
CVE-2021-38295
7.3

This is a privilege escalation vulnerability in Apache CouchDB where a malicious user with document creation permissions can attach HTML files contain...

Oct 14, 2021
CVE-2021-37695
7.3

CVE-2021-37695 is a cross-site scripting (XSS) vulnerability in CKEditor 4's Fake Objects plugin that allows attackers to inject malicious HTML that c...

Aug 13, 2021
CVE-2020-28470
7.3

This vulnerability in @scullyio/scully allows cross-site scripting (XSS) attacks through improper serialization of transfer state data. Attackers can ...

Jan 14, 2021
CVE-2020-28456
7.3

This vulnerability allows attackers to inject malicious scripts into the S-Cart admin panel, which could execute in administrators' browsers. It affec...

Dec 15, 2020
CVE-2020-15273
7.3

baserCMS versions 4.0.0 through 4.4.0 contain a cross-site scripting vulnerability in management interface components. Attackers with administrative a...

Oct 30, 2020
CVE-2020-15155
7.3

baserCMS 4.3.6 and earlier contains a cross-site scripting (XSS) vulnerability in toolbar.php that allows authenticated administrators to execute arbi...

Aug 28, 2020
CVE-2020-13283
7.3

This cross-site scripting (XSS) vulnerability in GitLab allows attackers to inject malicious scripts into milestone titles, which then execute in vict...

Aug 13, 2020
CVE-2020-4054
7.3

This CVE describes a cross-site scripting (XSS) vulnerability in the RubyGem sanitize library. When using the 'relaxed' configuration or custom config...

Jun 16, 2020
CVE-2026-1074
7.2

The WP App Bar WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into plugin settings....

Mar 7, 2026
CVE-2026-2365
7.2

The Fluent Forms Pro WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into draft form...

Mar 5, 2026
CVE-2026-1945
7.2

The WPBookit WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into w...

Mar 4, 2026
CVE-2019-25419
7.2

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the schedule endpoint. Attackers can inject malicious JavaScript vi...

Feb 19, 2026
CVE-2019-25422
7.2

CVE-2019-25422 is a cross-site scripting vulnerability in Comodo Dome Firewall that allows attackers to inject malicious JavaScript through the vpnfw ...

Feb 19, 2026
CVE-2019-25405
7.2

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the license activation endpoint. Attackers can inject malicious Jav...

Feb 19, 2026
CVE-2025-14452
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wpcr3_fname' parameter in the WP Customer Reviews WordPress p...

Feb 19, 2026
CVE-2026-27177
7.2

MajorDoMo contains an unauthenticated stored XSS vulnerability that allows attackers to inject malicious JavaScript into property values. When adminis...

Feb 18, 2026
CVE-2026-1931
7.2

The Rent Fetch WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in the 'keyword' parameter that allows unauthenticated atta...

Feb 18, 2026
CVE-2026-1216
7.2

The RSS Aggregator WordPress plugin is vulnerable to reflected cross-site scripting (XSS) via the 'template' parameter. Unauthenticated attackers can ...

Feb 17, 2026
CVE-2019-25394
7.2

This stored XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript through modem.cgi POST parameters. When users acce...

Feb 16, 2026
CVE-2019-25379
7.2

This stored and reflected XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript via the urlfilter.cgi endpoint. When...

Feb 16, 2026
CVE-2026-26930
7.2

This cross-site scripting (XSS) vulnerability in SmarterMail allows attackers to inject malicious scripts via MAPI requests. It affects organizations ...

Feb 16, 2026
CVE-2026-1843
7.2

The Super Page Cache WordPress plugin has a stored cross-site scripting vulnerability in its Activity Log feature. Unauthenticated attackers can injec...

Feb 14, 2026
CVE-2026-0753
7.2

This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in victims' browsers via the 'sscf_name' parameter in the Super Si...

Feb 14, 2026
CVE-2026-1841
7.2

The PixelYourSite WordPress plugin is vulnerable to stored cross-site scripting (XSS) via insufficient input sanitization in the 'pysTrafficSource' an...

Feb 13, 2026
CVE-2026-1320
7.2

The Secure Copy Content Protection and Content Locking WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'X-Forwarded-For' H...

Feb 12, 2026
CVE-2026-1316
7.2

This stored XSS vulnerability in the Customer Reviews for WooCommerce WordPress plugin allows attackers to inject malicious scripts into web pages via...

Feb 12, 2026
CVE-2025-15440
7.2

The iONE360 configurator WordPress plugin has a stored XSS vulnerability in its contact form parameters that allows unauthenticated attackers to injec...

Feb 11, 2026
CVE-2026-1866
7.2

The Name Directory WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via public submis...

Feb 10, 2026
CVE-2026-0617
7.2

This stored XSS vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to inject malicious scripts into customer profile fie...

Feb 3, 2026
CVE-2025-14554
7.2

This stored XSS vulnerability in the Sell BTC WordPress plugin allows unauthenticated attackers to inject malicious scripts into order records. When a...

Jan 31, 2026
CVE-2021-47897
7.2

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of change_params.php. Attackers can inject malicious...

Jan 23, 2026
CVE-2021-47892
7.2

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' field of the purchase page. Attacker...

Jan 23, 2026
CVE-2021-47873
7.2

This stored cross-site scripting vulnerability in VestaCP allows attackers to inject malicious scripts into the IP interface configuration. When admin...

Jan 21, 2026

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,867 CVEs classified as CWE-79, with 274 rated critical and 2,376 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free