CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,870)
The Wise Chat WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the X-Forwarded-Fo...
Jun 17, 2025The Xagio SEO WordPress plugin has a stored XSS vulnerability in all versions up to 7.1.0.16. Unauthenticated attackers can inject malicious scripts v...
Jun 11, 2025The Shared Files WordPress plugin allows unauthenticated attackers to upload HTML files containing malicious JavaScript, which executes when users acc...
Jun 3, 2025This vulnerability allows authenticated attackers with Custom-level access or higher in WordPress to inject malicious scripts via media upload names i...
Jun 3, 2025This cross-site scripting (XSS) vulnerability in Best Practical RT allows attackers to inject malicious scripts into search URLs. When users view sear...
May 28, 2025CVE-2025-31501 is a cross-site scripting (XSS) vulnerability in Best Practical RT (Request Tracker) that allows attackers to inject malicious JavaScri...
May 28, 2025The Solid Mail WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into email fields. Wh...
May 23, 2025The WP Content Security Plugin for WordPress has a stored cross-site scripting vulnerability in versions up to 2.3. Unauthenticated attackers can inje...
May 15, 2025CVE-2015-4582 is a cross-site scripting (XSS) vulnerability in the Boot Store WordPress theme version 1.6.4. It allows attackers to inject malicious s...
Apr 28, 2025The eForm WordPress Form Builder plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scri...
Apr 24, 2025The SMTP for Amazon SES – YaySMTP WordPress plugin has a stored cross-site scripting vulnerability in email logs. Unauthenticated attackers can inje...
Apr 11, 2025This Cross-Site Scripting (XSS) vulnerability in SquirrelMail allows attackers to inject malicious JavaScript via email headers. When exploited, it ca...
Apr 2, 2025The Booster for WooCommerce WordPress plugin has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject mal...
Apr 1, 2025KNIME Business Hub contains cross-site scripting vulnerabilities that allow attackers to execute arbitrary JavaScript in users' browsers when they cli...
Mar 31, 2025This vulnerability in MISP (Malware Information Sharing Platform) allows cross-site scripting (XSS) attacks through REST endpoints that return non-JSO...
Mar 28, 2025The Newsletters plugin for WordPress has a stored XSS vulnerability in its logging functionality that allows unauthenticated attackers to inject malic...
Mar 26, 2025The WP Church Donation plugin for WordPress has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious ...
Mar 25, 2025The WP Test Email plugin for WordPress has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scrip...
Mar 15, 2025This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the AppPresser plugin when logging is en...
Mar 13, 2025This stored XSS vulnerability in the Contest Gallery WordPress plugin allows unauthenticated attackers to inject malicious scripts into photo gallery ...
Feb 28, 2025The SMTP for SendGrid – YaySMTP WordPress plugin up to version 1.3.1 contains a stored cross-site scripting (XSS) vulnerability due to insufficient ...
Feb 22, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the SMTP for Sendinblue – YaySMTP plugin,...
Feb 22, 2025The Lenix Elementor Leads addon plugin for WordPress has a stored XSS vulnerability in URL form fields that allows unauthenticated attackers to inject...
Feb 20, 2025This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the YaySMTP plugin. When users visit compro...
Feb 19, 2025The Subscribe2 WordPress plugin has a stored XSS vulnerability in all versions up to 10.43. Unauthenticated attackers can inject malicious scripts via...
Feb 19, 2025The Post SMTP WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into ...
Feb 18, 2025The FormCraft WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when viewed. This st...
Feb 18, 2025The Welcart e-Commerce plugin for WordPress has a stored cross-site scripting (XSS) vulnerability in the 'name' parameter that allows unauthenticated ...
Feb 12, 2025This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the HT Me...
Feb 11, 2025This vulnerability allows unauthenticated attackers to upload malicious dfxp files containing JavaScript that executes automatically when accessed. It...
Jan 31, 2025The Link Fixer WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages. T...
Jan 31, 2025This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Flexible Wishlist for WooCommerce pl...
Jan 29, 2025The Gravity Forms WordPress plugin has a stored XSS vulnerability in the 'alt' parameter that allows unauthenticated attackers to inject malicious scr...
Jan 17, 2025IBM CICS TX Advanced and Standard are vulnerable to stored cross-site scripting (XSS) that allows authenticated users to inject malicious JavaScript i...
Jan 16, 2025This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the...
Jan 15, 2025This stored XSS vulnerability in the Frontend Admin WordPress plugin allows unauthenticated attackers to inject malicious scripts into submission form...
Dec 14, 2024This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the Ninja Forms plugin. When users visit...
Dec 12, 2024The Activity Log plugin for WordPress has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into administra...
Nov 21, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress websites using the GDPR plugin. When users visit pages ...
Nov 19, 2024The WP Activity Log plugin for WordPress has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the user...
Nov 15, 2024The Tripetto WordPress plugin has a stored cross-site scripting vulnerability in file upload functionality that allows unauthenticated attackers to in...
Nov 15, 2024This stored XSS vulnerability in the WPAdverts WordPress plugin allows unauthenticated attackers to inject malicious scripts into website pages via th...
Oct 30, 2024The SendPulse Free Web Push WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious...
Oct 17, 2024The Rich Review WordPress plugin versions up to 1.7.4 contain a stored cross-site scripting vulnerability in the 'update' POST parameter. Unauthentica...
Oct 16, 2024The SlimStat Analytics WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into visitor ...
Oct 15, 2024This is a stored cross-site scripting (XSS) vulnerability in LibreNMS where administrators can inject malicious JavaScript into Device Group names. Wh...
Oct 1, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using The Events Calendar plugin. When users view...
Sep 27, 2024The WordPress Visitors plugin up to version 1.0 has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via s...
Sep 26, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Contact Form to Any API plugin. When us...
Sep 25, 2024This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the Thanh Toán Quét Mã QR Code Tự �...
Sep 25, 2024About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free