CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,870
Total CVEs
275
Critical
2,378
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,870)

CVE-2024-7134
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the LiquidPoll plugin. When users visit ...

Aug 21, 2024
CVE-2024-7301
7.2

The WordPress File Upload plugin versions up to 4.24.8 contain a stored cross-site scripting vulnerability in SVG file uploads. Unauthenticated attack...

Aug 16, 2024
CVE-2024-43369
7.2

This vulnerability allows authenticated users with content editing permissions (typically Editor role or higher) to inject malicious scripts into Rich...

Aug 16, 2024
CVE-2024-41809
7.2

OpenObserve versions 0.4.4 through 0.9.x contain a cross-site scripting (XSS) vulnerability in the MemberSubscription.vue component. This allows attac...

Jul 25, 2024
CVE-2024-6753
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Social Auto Poster plugin. When users v...

Jul 24, 2024
CVE-2024-5902
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress feedback forms via the name parameter. When high-privil...

Jul 12, 2024
CVE-2024-28798
7.2

IBM InfoSphere Information Server 11.7 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious ...

Jun 30, 2024
CVE-2024-5791
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wp_id' parameter in the vcita WordPress plugin. The scripts e...

Jun 22, 2024
CVE-2024-5542
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Master Addons plugin's Navigation Menu ...

Jun 7, 2024
CVE-2024-4455
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the YITH WooCommerce Ajax Search plugin....

May 24, 2024
CVE-2024-4709
7.2

This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into website pages vi...

May 18, 2024
CVE-2024-3045
7.2

This stored XSS vulnerability in the PDF Invoices & Packing Slips for WooCommerce WordPress plugin allows unauthenticated attackers to inject maliciou...

May 2, 2024
CVE-2024-2082
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the EleForms plugin. The scripts execute wh...

May 2, 2024
CVE-2023-6961
7.2

The WP Meta SEO WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the Referer HTTP header. Unauthenticated attackers can inject ...

May 2, 2024
CVE-2024-3600
7.2

This vulnerability in the Poll Maker WordPress plugin allows unauthenticated attackers to create malicious quizzes with stored cross-site scripting (X...

Apr 19, 2024
CVE-2024-32345
7.2

This cross-site scripting (XSS) vulnerability in CMSimple v5.15 allows attackers to inject malicious scripts into the Settings menu's Language Configu...

Apr 17, 2024
CVE-2024-1852
7.2

The WP-Members Membership Plugin for WordPress has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject m...

Apr 9, 2024
CVE-2024-29882
7.2

This CVE describes a cross-site scripting (XSS) vulnerability in SRS video server's API endpoint. Attackers can inject malicious JavaScript via the ca...

Mar 28, 2024
CVE-2024-28092
7.2

This vulnerability allows remote attackers within Wi-Fi range to inject malicious scripts into multiple administrative web pages of UBEE DDW365 router...

Mar 19, 2024
CVE-2024-1935
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the RafflePress plugin. When users visit...

Mar 13, 2024
CVE-2024-25155
7.2

This is a cross-site scripting (XSS) vulnerability in FileCatalyst Direct web server versions 3.8.6 through 3.8.8. Attackers can craft malicious URLs ...

Mar 13, 2024
CVE-2024-2123
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Ultimate Member plugin. When users visi...

Mar 13, 2024
CVE-2024-0386
7.2

The weForms WordPress plugin has a stored XSS vulnerability in versions up to 1.6.21 where attackers can inject malicious scripts via the 'Referer' HT...

Mar 12, 2024
CVE-2023-7063
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using WPForms Pro plugin. When users visit pages ...

Jan 20, 2024
CVE-2023-6828
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the ARForms Form Builder plugin. When us...

Jan 11, 2024
CVE-2023-7027
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the POST SMTP Mailer plugin. When users vis...

Jan 3, 2024
CVE-2021-38927
7.2

IBM Aspera Console 3.4.0 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interfa...

Dec 25, 2023
CVE-2022-48192
7.2

This CVE describes a cross-site scripting (XSS) vulnerability in Softing smartLink SW-HT software versions before 1.30. Attackers can inject malicious...

Nov 6, 2023
CVE-2022-4712
7.2

The WP Cerber Security plugin for WordPress versions up to 9.1 contains a stored cross-site scripting (XSS) vulnerability in the log parameter during ...

Oct 20, 2023
CVE-2023-5538
7.2

The MpOperationLogs WordPress plugin up to version 1.0.1 contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attack...

Oct 18, 2023
CVE-2023-43657
7.2

This vulnerability in the discourse-encrypt plugin allows cross-site scripting (XSS) attacks when encrypted topic titles are improperly escaped. It af...

Sep 28, 2023
CVE-2023-4308
7.2

The User Submitted Posts WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into websit...

Aug 15, 2023
CVE-2023-3388
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Beautiful Cookie Consent Banner plug...

Jun 24, 2023
CVE-2023-0992
7.2

The Shield Security WordPress plugin up to version 17.0.17 contains a stored XSS vulnerability in the User-Agent header handling. Unauthenticated atta...

Jun 9, 2023
CVE-2021-4358
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the WP DSGVO Tools (GDPR) plugin, which exe...

Jun 7, 2023
CVE-2021-4365
7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Frontend File Manager plugin. When user...

Jun 7, 2023
CVE-2019-25140
7.2

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Coming Soon Page & Maintenance Mode ...

Jun 7, 2023
CVE-2019-25145
7.2

This vulnerability allows unauthenticated attackers to inject arbitrary HTML into emails sent by the PirateForms WordPress plugin. This enables phishi...

Jun 7, 2023
CVE-2019-25147
7.2

The Pretty Links WordPress plugin up to version 2.1.9 has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject ...

Jun 7, 2023
CVE-2023-2298
7.2

This stored XSS vulnerability in the vcita WordPress plugin allows unauthenticated attackers to inject malicious JavaScript via the 'business_id' para...

Jun 3, 2023
CVE-2022-2219
7.2

This vulnerability in the Unyson WordPress plugin allows attackers to inject malicious scripts into web pages viewed by other users. It affects WordPr...

Jul 25, 2022
CVE-2021-32585
7.2

This stored cross-site scripting (XSS) vulnerability in FortiWAN allows attackers to inject malicious scripts into web pages via crafted HTTP requests...

Apr 6, 2022
CVE-2022-0834
7.2

The Amelia WordPress plugin has a stored cross-site scripting (XSS) vulnerability in versions up to 1.0.46. Attackers can inject malicious scripts via...

Mar 23, 2022
CVE-2022-25305
7.2

This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's IP parameter. When site administrators view ...

Feb 24, 2022
CVE-2022-25307
7.2

This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's platform parameter. When site administrators...

Feb 24, 2022
CVE-2020-15092
7.2

CVE-2020-15092 is a cross-site scripting (XSS) vulnerability in TimelineJS that allows attackers to execute malicious JavaScript by injecting HTML int...

Jul 9, 2020
CVE-2026-27072
7.1

This stored cross-site scripting (XSS) vulnerability in the PixelYourSite WordPress plugin allows attackers to inject malicious scripts that execute w...

Feb 20, 2026
CVE-2026-24949
7.1

This DOM-based cross-site scripting (XSS) vulnerability in the PhotoMe WordPress theme allows attackers to inject malicious scripts into web pages vie...

Feb 20, 2026
CVE-2026-24943
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Grand Conference WordPress theme. When users visit a s...

Feb 20, 2026
CVE-2026-22357
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Link Whisper Free WordPress plugin. Attackers can inject malicious scripts via cra...

Feb 20, 2026

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free