CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,870)
This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the LiquidPoll plugin. When users visit ...
Aug 21, 2024The WordPress File Upload plugin versions up to 4.24.8 contain a stored cross-site scripting vulnerability in SVG file uploads. Unauthenticated attack...
Aug 16, 2024This vulnerability allows authenticated users with content editing permissions (typically Editor role or higher) to inject malicious scripts into Rich...
Aug 16, 2024OpenObserve versions 0.4.4 through 0.9.x contain a cross-site scripting (XSS) vulnerability in the MemberSubscription.vue component. This allows attac...
Jul 25, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Social Auto Poster plugin. When users v...
Jul 24, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress feedback forms via the name parameter. When high-privil...
Jul 12, 2024IBM InfoSphere Information Server 11.7 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious ...
Jun 30, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wp_id' parameter in the vcita WordPress plugin. The scripts e...
Jun 22, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Master Addons plugin's Navigation Menu ...
Jun 7, 2024This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the YITH WooCommerce Ajax Search plugin....
May 24, 2024This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into website pages vi...
May 18, 2024This stored XSS vulnerability in the PDF Invoices & Packing Slips for WooCommerce WordPress plugin allows unauthenticated attackers to inject maliciou...
May 2, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the EleForms plugin. The scripts execute wh...
May 2, 2024The WP Meta SEO WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the Referer HTTP header. Unauthenticated attackers can inject ...
May 2, 2024This vulnerability in the Poll Maker WordPress plugin allows unauthenticated attackers to create malicious quizzes with stored cross-site scripting (X...
Apr 19, 2024This cross-site scripting (XSS) vulnerability in CMSimple v5.15 allows attackers to inject malicious scripts into the Settings menu's Language Configu...
Apr 17, 2024The WP-Members Membership Plugin for WordPress has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject m...
Apr 9, 2024This CVE describes a cross-site scripting (XSS) vulnerability in SRS video server's API endpoint. Attackers can inject malicious JavaScript via the ca...
Mar 28, 2024This vulnerability allows remote attackers within Wi-Fi range to inject malicious scripts into multiple administrative web pages of UBEE DDW365 router...
Mar 19, 2024This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the RafflePress plugin. When users visit...
Mar 13, 2024This is a cross-site scripting (XSS) vulnerability in FileCatalyst Direct web server versions 3.8.6 through 3.8.8. Attackers can craft malicious URLs ...
Mar 13, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Ultimate Member plugin. When users visi...
Mar 13, 2024The weForms WordPress plugin has a stored XSS vulnerability in versions up to 1.6.21 where attackers can inject malicious scripts via the 'Referer' HT...
Mar 12, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using WPForms Pro plugin. When users visit pages ...
Jan 20, 2024This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the ARForms Form Builder plugin. When us...
Jan 11, 2024This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the POST SMTP Mailer plugin. When users vis...
Jan 3, 2024IBM Aspera Console 3.4.0 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interfa...
Dec 25, 2023This CVE describes a cross-site scripting (XSS) vulnerability in Softing smartLink SW-HT software versions before 1.30. Attackers can inject malicious...
Nov 6, 2023The WP Cerber Security plugin for WordPress versions up to 9.1 contains a stored cross-site scripting (XSS) vulnerability in the log parameter during ...
Oct 20, 2023The MpOperationLogs WordPress plugin up to version 1.0.1 contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attack...
Oct 18, 2023This vulnerability in the discourse-encrypt plugin allows cross-site scripting (XSS) attacks when encrypted topic titles are improperly escaped. It af...
Sep 28, 2023The User Submitted Posts WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into websit...
Aug 15, 2023This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Beautiful Cookie Consent Banner plug...
Jun 24, 2023The Shield Security WordPress plugin up to version 17.0.17 contains a stored XSS vulnerability in the User-Agent header handling. Unauthenticated atta...
Jun 9, 2023This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the WP DSGVO Tools (GDPR) plugin, which exe...
Jun 7, 2023This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Frontend File Manager plugin. When user...
Jun 7, 2023This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress sites using the Coming Soon Page & Maintenance Mode ...
Jun 7, 2023This vulnerability allows unauthenticated attackers to inject arbitrary HTML into emails sent by the PirateForms WordPress plugin. This enables phishi...
Jun 7, 2023The Pretty Links WordPress plugin up to version 2.1.9 has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject ...
Jun 7, 2023This stored XSS vulnerability in the vcita WordPress plugin allows unauthenticated attackers to inject malicious JavaScript via the 'business_id' para...
Jun 3, 2023This vulnerability in the Unyson WordPress plugin allows attackers to inject malicious scripts into web pages viewed by other users. It affects WordPr...
Jul 25, 2022This stored cross-site scripting (XSS) vulnerability in FortiWAN allows attackers to inject malicious scripts into web pages via crafted HTTP requests...
Apr 6, 2022The Amelia WordPress plugin has a stored cross-site scripting (XSS) vulnerability in versions up to 1.0.46. Attackers can inject malicious scripts via...
Mar 23, 2022This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's IP parameter. When site administrators view ...
Feb 24, 2022This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's platform parameter. When site administrators...
Feb 24, 2022CVE-2020-15092 is a cross-site scripting (XSS) vulnerability in TimelineJS that allows attackers to execute malicious JavaScript by injecting HTML int...
Jul 9, 2020This stored cross-site scripting (XSS) vulnerability in the PixelYourSite WordPress plugin allows attackers to inject malicious scripts that execute w...
Feb 20, 2026This DOM-based cross-site scripting (XSS) vulnerability in the PhotoMe WordPress theme allows attackers to inject malicious scripts into web pages vie...
Feb 20, 2026This vulnerability allows attackers to inject malicious scripts into web pages generated by the Grand Conference WordPress theme. When users visit a s...
Feb 20, 2026This is a reflected cross-site scripting (XSS) vulnerability in the Link Whisper Free WordPress plugin. Attackers can inject malicious scripts via cra...
Feb 20, 2026About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free