CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,870
Total CVEs
275
Critical
2,378
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,870)

CVE-2025-3774
7.2

The Wise Chat WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the X-Forwarded-Fo...

Jun 17, 2025
CVE-2025-3302
7.2

The Xagio SEO WordPress plugin has a stored XSS vulnerability in all versions up to 7.1.0.16. Unauthenticated attackers can inject malicious scripts v...

Jun 11, 2025
CVE-2025-4392
7.2

The Shared Files WordPress plugin allows unauthenticated attackers to upload HTML files containing malicious JavaScript, which executes when users acc...

Jun 3, 2025
CVE-2025-4224
7.2

This vulnerability allows authenticated attackers with Custom-level access or higher in WordPress to inject malicious scripts via media upload names i...

Jun 3, 2025
CVE-2025-30087
7.2

This cross-site scripting (XSS) vulnerability in Best Practical RT allows attackers to inject malicious scripts into search URLs. When users view sear...

May 28, 2025
CVE-2025-31501
7.2

CVE-2025-31501 is a cross-site scripting (XSS) vulnerability in Best Practical RT (Request Tracker) that allows attackers to inject malicious JavaScri...

May 28, 2025
CVE-2025-1123
7.2

The Solid Mail WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into email fields. Wh...

May 23, 2025
CVE-2025-4579
7.2

The WP Content Security Plugin for WordPress has a stored cross-site scripting vulnerability in versions up to 2.3. Unauthenticated attackers can inje...

May 15, 2025
CVE-2015-4582
7.2

CVE-2015-4582 is a cross-site scripting (XSS) vulnerability in the Boot Store WordPress theme version 1.6.4. It allows attackers to inject malicious s...

Apr 28, 2025
CVE-2025-1294
7.2

The eForm WordPress Form Builder plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scri...

Apr 24, 2025
CVE-2025-3434
7.2

The SMTP for Amazon SES – YaySMTP WordPress plugin has a stored cross-site scripting vulnerability in email logs. Unauthenticated attackers can inje...

Apr 11, 2025
CVE-2025-30090
7.2

This Cross-Site Scripting (XSS) vulnerability in SquirrelMail allows attackers to inject malicious JavaScript via email headers. When exploited, it ca...

Apr 2, 2025
CVE-2024-12278
7.2

The Booster for WooCommerce WordPress plugin has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject mal...

Apr 1, 2025
CVE-2025-3019
7.2

KNIME Business Hub contains cross-site scripting vulnerabilities that allow attackers to execute arbitrary JavaScript in users' browsers when they cli...

Mar 31, 2025
CVE-2024-58130
7.2

This vulnerability in MISP (Malware Information Sharing Platform) allows cross-site scripting (XSS) attacks through REST endpoints that return non-JSO...

Mar 28, 2025
CVE-2025-2009
7.2

The Newsletters plugin for WordPress has a stored XSS vulnerability in its logging functionality that allows unauthenticated attackers to inject malic...

Mar 26, 2025
CVE-2024-13690
7.2

The WP Church Donation plugin for WordPress has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious ...

Mar 25, 2025
CVE-2025-2325
7.2

The WP Test Email plugin for WordPress has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scrip...

Mar 15, 2025
CVE-2025-1561
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the AppPresser plugin when logging is en...

Mar 13, 2025
CVE-2025-1513
7.2

This stored XSS vulnerability in the Contest Gallery WordPress plugin allows unauthenticated attackers to inject malicious scripts into photo gallery ...

Feb 28, 2025
CVE-2025-0918
7.2

The SMTP for SendGrid – YaySMTP WordPress plugin up to version 1.3.1 contains a stored cross-site scripting (XSS) vulnerability due to insufficient ...

Feb 22, 2025
CVE-2025-0953
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the SMTP for Sendinblue – YaySMTP plugin,...

Feb 22, 2025
CVE-2025-1039
7.2

The Lenix Elementor Leads addon plugin for WordPress has a stored XSS vulnerability in URL form fields that allows unauthenticated attackers to inject...

Feb 20, 2025
CVE-2025-0916
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the YaySMTP plugin. When users visit compro...

Feb 19, 2025
CVE-2024-11582
7.2

The Subscribe2 WordPress plugin has a stored XSS vulnerability in all versions up to 10.43. Unauthenticated attackers can inject malicious scripts via...

Feb 19, 2025
CVE-2025-0521
7.2

The Post SMTP WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into ...

Feb 18, 2025
CVE-2025-0817
7.2

The FormCraft WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when viewed. This st...

Feb 18, 2025
CVE-2025-0511
7.2

The Welcart e-Commerce plugin for WordPress has a stored cross-site scripting (XSS) vulnerability in the 'name' parameter that allows unauthenticated ...

Feb 12, 2025
CVE-2024-12599
7.2

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the HT Me...

Feb 11, 2025
CVE-2024-13504
7.2

This vulnerability allows unauthenticated attackers to upload malicious dfxp files containing JavaScript that executes automatically when accessed. It...

Jan 31, 2025
CVE-2025-0809
7.2

The Link Fixer WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages. T...

Jan 31, 2025
CVE-2024-13696
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Flexible Wishlist for WooCommerce pl...

Jan 29, 2025
CVE-2024-13377
7.2

The Gravity Forms WordPress plugin has a stored XSS vulnerability in the 'alt' parameter that allows unauthenticated attackers to inject malicious scr...

Jan 17, 2025
CVE-2024-41746
7.2

IBM CICS TX Advanced and Standard are vulnerable to stored cross-site scripting (XSS) that allows authenticated users to inject malicious JavaScript i...

Jan 16, 2025
CVE-2024-13351
7.2

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the...

Jan 15, 2025
CVE-2024-11720
7.2

This stored XSS vulnerability in the Frontend Admin WordPress plugin allows unauthenticated attackers to inject malicious scripts into submission form...

Dec 14, 2024
CVE-2024-11052
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the Ninja Forms plugin. When users visit...

Dec 12, 2024
CVE-2024-10788
7.2

The Activity Log plugin for WordPress has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into administra...

Nov 21, 2024
CVE-2024-10388
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress websites using the GDPR plugin. When users visit pages ...

Nov 19, 2024
CVE-2024-10793
7.2

The WP Activity Log plugin for WordPress has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via the user...

Nov 15, 2024
CVE-2024-10260
7.2

The Tripetto WordPress plugin has a stored cross-site scripting vulnerability in file upload functionality that allows unauthenticated attackers to in...

Nov 15, 2024
CVE-2024-10108
7.2

This stored XSS vulnerability in the WPAdverts WordPress plugin allows unauthenticated attackers to inject malicious scripts into website pages via th...

Oct 30, 2024
CVE-2024-9184
7.2

The SendPulse Free Web Push WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious...

Oct 17, 2024
CVE-2019-25216
7.2

The Rich Review WordPress plugin versions up to 1.7.4 contain a stored cross-site scripting vulnerability in the 'update' POST parameter. Unauthentica...

Oct 16, 2024
CVE-2024-9548
7.2

The SlimStat Analytics WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into visitor ...

Oct 15, 2024
CVE-2024-47524
7.2

This is a stored cross-site scripting (XSS) vulnerability in LibreNMS where administrators can inject malicious JavaScript into Device Group names. Wh...

Oct 1, 2024
CVE-2024-6931
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using The Events Calendar plugin. When users view...

Sep 27, 2024
CVE-2022-4541
7.2

The WordPress Visitors plugin up to version 1.0 has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via s...

Sep 26, 2024
CVE-2024-7617
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Contact Form to Any API plugin. When us...

Sep 25, 2024
CVE-2024-8914
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the Thanh Toán Quét Mã QR Code Tự �...

Sep 25, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free