CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,867
Total CVEs
274
Critical
2,376
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,867)

CVE-2021-47855
7.2

OpenLiteSpeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows attackers to inject malicious ...

Jan 21, 2026
CVE-2021-47857
7.2

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in calendar event subtitles that allows attackers to inject malicious JavaScrip...

Jan 21, 2026
CVE-2021-47858
7.2

This stored cross-site scripting vulnerability in Genexis Platinum-4410 routers allows attackers to inject malicious scripts into the 'start_addr' par...

Jan 21, 2026
CVE-2025-15380
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the NotificationX plugin. When users visit ...

Jan 20, 2026
CVE-2021-47842
7.2

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability where attackers can upload malicious markdown files containing JavaScript paylo...

Jan 16, 2026
CVE-2021-47837
7.2

Markdownify 1.2.0 contains a persistent cross-site scripting (XSS) vulnerability that allows attackers to upload malicious markdown files containing e...

Jan 16, 2026
CVE-2021-47838
7.2

Markright 1.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When us...

Jan 16, 2026
CVE-2021-47839
7.2

CVE-2021-47839 is a persistent cross-site scripting (XSS) vulnerability in Marky 0.0.1 that allows attackers to inject malicious JavaScript into markd...

Jan 16, 2026
CVE-2021-47840
7.2

Moeditor 0.2.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When v...

Jan 16, 2026
CVE-2021-47835
7.2

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious scripts in custom widget titles and fi...

Jan 16, 2026
CVE-2025-31510
7.2

This CVE describes a cross-site scripting (XSS) vulnerability in LemonLDAP::NG's portal login page. Attackers can inject malicious scripts via the tab...

Jan 16, 2026
CVE-2025-15283
7.2

The Name Directory WordPress plugin up to version 1.30.3 has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inje...

Jan 14, 2026
CVE-2025-15378
7.2

The AJS Footnotes WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages...

Jan 14, 2026
CVE-2025-15266
7.2

This stored XSS vulnerability in the GeekyBot WordPress plugin allows unauthenticated attackers to inject malicious scripts via chat messages. When ad...

Jan 14, 2026
CVE-2025-14937
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Frontend Admin plugin. The injected ...

Jan 9, 2026
CVE-2025-15055
7.2

The SlimStat Analytics WordPress plugin has a stored XSS vulnerability in versions up to 5.3.4 that allows unauthenticated attackers to inject malicio...

Jan 9, 2026
CVE-2025-15057
7.2

The SlimStat Analytics WordPress plugin has a stored XSS vulnerability in all versions up to 5.3.3. Unauthenticated attackers can inject malicious scr...

Jan 9, 2026
CVE-2026-21873
7.2

This vulnerability in NiceGUI allows attackers to manipulate URL fragment identifiers via cross-site iframe attacks, potentially enabling UI manipulat...

Jan 8, 2026
CVE-2025-66648
7.2

CVE-2025-66648 is a cross-site scripting (XSS) vulnerability in vega-functions library that allows attackers to execute arbitrary JavaScript code by e...

Jan 5, 2026
CVE-2022-50787
7.2

CVE-2022-50787 is an unauthenticated stored cross-site scripting vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco software versions 2.x. Attackers can i...

Dec 30, 2025
CVE-2025-14855
7.2

The SureForms WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into ...

Dec 21, 2025
CVE-2025-9343
7.2

The ELEX WordPress HelpDesk & Customer Ticketing System plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject maliciou...

Dec 21, 2025
CVE-2025-68385
7.2

This CVE describes a cross-site scripting (XSS) vulnerability in Vega visualization components that allows authenticated users to inject malicious scr...

Dec 18, 2025
CVE-2025-68461
7.2

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail that allows attackers to inject malicious scripts via the animate t...

Dec 18, 2025
CVE-2025-12570
7.2

The Fancy Product Designer WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when vi...

Dec 12, 2025
CVE-2025-13604
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the CleanTalk security plugin. When users v...

Dec 9, 2025
CVE-2025-12705
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Social Reviews & Recommendations plugin...

Dec 9, 2025
CVE-2025-12510
7.2

The Widgets for Google Reviews WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into ...

Dec 6, 2025
CVE-2025-11727
7.2

This stored XSS vulnerability in the Omnichannel for WooCommerce plugin allows unauthenticated attackers to inject malicious scripts that execute when...

Dec 4, 2025
CVE-2025-13692
7.2

The Unlimited Elements For Elementor WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that execut...

Nov 27, 2025
CVE-2025-13068
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Telegram Bot & Channel plugin. When use...

Nov 25, 2025
CVE-2025-12160
7.2

The Simple User Registration plugin for WordPress has a stored cross-site scripting vulnerability in the 'wpr_admin_msg' parameter. Unauthenticated at...

Nov 21, 2025
CVE-2025-12135
7.2

The WPBookit WordPress plugin up to version 1.0.6 has a stored cross-site scripting vulnerability in the 'css_code' parameter. Unauthenticated attacke...

Nov 21, 2025
CVE-2025-0643
7.2

This stored XSS vulnerability in Pyxis Signage allows attackers to inject malicious scripts into web pages that are then executed when other users vie...

Nov 20, 2025
CVE-2025-13206
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the GiveWP donation plugin. The stored X...

Nov 19, 2025
CVE-2025-12484
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the RafflePress plugin. The stored XSS exec...

Nov 19, 2025
CVE-2025-11994
7.2

The Easy Email Subscription WordPress plugin has a stored XSS vulnerability in the 'name' parameter that allows unauthenticated attackers to inject ma...

Nov 12, 2025
CVE-2025-11733
7.2

The Footnotes Made Easy WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scr...

Nov 4, 2025
CVE-2025-59837
7.2

This vulnerability in Astro's image proxy allows attackers to bypass domain validation by using backslashes in the href parameter, enabling server-sid...

Oct 28, 2025
CVE-2025-11238
7.2

The Watu Quiz WordPress plugin versions ≤3.4.4 have a stored XSS vulnerability when the 'Save source URL' option is enabled. Unauthenticated attacke...

Oct 25, 2025
CVE-2025-57150
7.2

This vulnerability allows attackers to inject malicious scripts into the Complaint Management System's admin interface via the categoryName parameter....

Sep 3, 2025
CVE-2025-50891
7.2

This vulnerability allows attackers to inject HTML or execute arbitrary code via cookie hijacking in Adform Site Tracking server-side backend. It affe...

Aug 19, 2025
CVE-2025-54421
7.2

This cross-site scripting (XSS) vulnerability in NamelessMC allows authenticated attackers to inject malicious scripts into web pages via the default_...

Aug 18, 2025
CVE-2025-7050
7.2

The Use-your-Drive WordPress plugin has a stored XSS vulnerability in the 'title' parameter of file metadata. Attackers can inject malicious scripts t...

Aug 5, 2025
CVE-2025-54597
7.2

This vulnerability allows attackers to inject malicious scripts via the 'q' parameter in LinuxServer.io Heimdall, potentially compromising user sessio...

Jul 27, 2025
CVE-2025-2800
7.2

This stored XSS vulnerability in the WP Event Manager plugin allows unauthenticated attackers to inject malicious JavaScript into event organizer name...

Jul 16, 2025
CVE-2024-9017
7.2

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to inject malicious JavaScript into group descriptions ...

Jul 3, 2025
CVE-2025-6212
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Ultra Addons for Contact Form 7 plugin....

Jun 26, 2025
CVE-2025-3774
7.2

The Wise Chat WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the X-Forwarded-Fo...

Jun 17, 2025
CVE-2025-3302
7.2

The Xagio SEO WordPress plugin has a stored XSS vulnerability in all versions up to 7.1.0.16. Unauthenticated attackers can inject malicious scripts v...

Jun 11, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,867 CVEs classified as CWE-79, with 274 rated critical and 2,376 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free