CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,867)
OpenLiteSpeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows attackers to inject malicious ...
Jan 21, 2026Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in calendar event subtitles that allows attackers to inject malicious JavaScrip...
Jan 21, 2026This stored cross-site scripting vulnerability in Genexis Platinum-4410 routers allows attackers to inject malicious scripts into the 'start_addr' par...
Jan 21, 2026This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the NotificationX plugin. When users visit ...
Jan 20, 2026StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability where attackers can upload malicious markdown files containing JavaScript paylo...
Jan 16, 2026Markdownify 1.2.0 contains a persistent cross-site scripting (XSS) vulnerability that allows attackers to upload malicious markdown files containing e...
Jan 16, 2026Markright 1.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When us...
Jan 16, 2026CVE-2021-47839 is a persistent cross-site scripting (XSS) vulnerability in Marky 0.0.1 that allows attackers to inject malicious JavaScript into markd...
Jan 16, 2026Moeditor 0.2.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When v...
Jan 16, 2026Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious scripts in custom widget titles and fi...
Jan 16, 2026This CVE describes a cross-site scripting (XSS) vulnerability in LemonLDAP::NG's portal login page. Attackers can inject malicious scripts via the tab...
Jan 16, 2026The Name Directory WordPress plugin up to version 1.30.3 has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inje...
Jan 14, 2026The AJS Footnotes WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages...
Jan 14, 2026This stored XSS vulnerability in the GeekyBot WordPress plugin allows unauthenticated attackers to inject malicious scripts via chat messages. When ad...
Jan 14, 2026This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Frontend Admin plugin. The injected ...
Jan 9, 2026The SlimStat Analytics WordPress plugin has a stored XSS vulnerability in versions up to 5.3.4 that allows unauthenticated attackers to inject malicio...
Jan 9, 2026The SlimStat Analytics WordPress plugin has a stored XSS vulnerability in all versions up to 5.3.3. Unauthenticated attackers can inject malicious scr...
Jan 9, 2026This vulnerability in NiceGUI allows attackers to manipulate URL fragment identifiers via cross-site iframe attacks, potentially enabling UI manipulat...
Jan 8, 2026CVE-2025-66648 is a cross-site scripting (XSS) vulnerability in vega-functions library that allows attackers to execute arbitrary JavaScript code by e...
Jan 5, 2026CVE-2022-50787 is an unauthenticated stored cross-site scripting vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco software versions 2.x. Attackers can i...
Dec 30, 2025The SureForms WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into ...
Dec 21, 2025The ELEX WordPress HelpDesk & Customer Ticketing System plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject maliciou...
Dec 21, 2025This CVE describes a cross-site scripting (XSS) vulnerability in Vega visualization components that allows authenticated users to inject malicious scr...
Dec 18, 2025This CVE describes a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail that allows attackers to inject malicious scripts via the animate t...
Dec 18, 2025The Fancy Product Designer WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when vi...
Dec 12, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the CleanTalk security plugin. When users v...
Dec 9, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Social Reviews & Recommendations plugin...
Dec 9, 2025The Widgets for Google Reviews WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into ...
Dec 6, 2025This stored XSS vulnerability in the Omnichannel for WooCommerce plugin allows unauthenticated attackers to inject malicious scripts that execute when...
Dec 4, 2025The Unlimited Elements For Elementor WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that execut...
Nov 27, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Telegram Bot & Channel plugin. When use...
Nov 25, 2025The Simple User Registration plugin for WordPress has a stored cross-site scripting vulnerability in the 'wpr_admin_msg' parameter. Unauthenticated at...
Nov 21, 2025The WPBookit WordPress plugin up to version 1.0.6 has a stored cross-site scripting vulnerability in the 'css_code' parameter. Unauthenticated attacke...
Nov 21, 2025This stored XSS vulnerability in Pyxis Signage allows attackers to inject malicious scripts into web pages that are then executed when other users vie...
Nov 20, 2025This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the GiveWP donation plugin. The stored X...
Nov 19, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the RafflePress plugin. The stored XSS exec...
Nov 19, 2025The Easy Email Subscription WordPress plugin has a stored XSS vulnerability in the 'name' parameter that allows unauthenticated attackers to inject ma...
Nov 12, 2025The Footnotes Made Easy WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scr...
Nov 4, 2025This vulnerability in Astro's image proxy allows attackers to bypass domain validation by using backslashes in the href parameter, enabling server-sid...
Oct 28, 2025The Watu Quiz WordPress plugin versions ≤3.4.4 have a stored XSS vulnerability when the 'Save source URL' option is enabled. Unauthenticated attacke...
Oct 25, 2025This vulnerability allows attackers to inject malicious scripts into the Complaint Management System's admin interface via the categoryName parameter....
Sep 3, 2025This vulnerability allows attackers to inject HTML or execute arbitrary code via cookie hijacking in Adform Site Tracking server-side backend. It affe...
Aug 19, 2025This cross-site scripting (XSS) vulnerability in NamelessMC allows authenticated attackers to inject malicious scripts into web pages via the default_...
Aug 18, 2025The Use-your-Drive WordPress plugin has a stored XSS vulnerability in the 'title' parameter of file metadata. Attackers can inject malicious scripts t...
Aug 5, 2025This vulnerability allows attackers to inject malicious scripts via the 'q' parameter in LinuxServer.io Heimdall, potentially compromising user sessio...
Jul 27, 2025This stored XSS vulnerability in the WP Event Manager plugin allows unauthenticated attackers to inject malicious JavaScript into event organizer name...
Jul 16, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to inject malicious JavaScript into group descriptions ...
Jul 3, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Ultra Addons for Contact Form 7 plugin....
Jun 26, 2025The Wise Chat WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the X-Forwarded-Fo...
Jun 17, 2025The Xagio SEO WordPress plugin has a stored XSS vulnerability in all versions up to 7.1.0.16. Unauthenticated attackers can inject malicious scripts v...
Jun 11, 2025About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,867 CVEs classified as CWE-79, with 274 rated critical and 2,376 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free