CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,870
Total CVEs
275
Critical
2,378
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,870)

CVE-2025-68041
7.1

This stored cross-site scripting (XSS) vulnerability in the Codisto Omnichannel for WooCommerce plugin allows attackers to inject malicious scripts in...

Jan 22, 2026
CVE-2025-68008
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP Mail plugin, which are then executed in victims' br...

Jan 22, 2026
CVE-2025-68010
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Netgsm WordPress plugin. When users visit specially cr...

Jan 22, 2026
CVE-2025-68011
7.1

This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users through improper input sanitization in the GLS Sh...

Jan 22, 2026
CVE-2025-68012
7.1

This stored cross-site scripting (XSS) vulnerability in the CodeColorer WordPress plugin allows attackers to inject malicious scripts into web pages t...

Jan 22, 2026
CVE-2025-68004
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the My Post Order WordPress plugin. When users visit a spe...

Jan 22, 2026
CVE-2025-67959
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the WorkScout WordPress theme. Attackers can inject malicious scripts via crafted URLs...

Jan 22, 2026
CVE-2025-67960
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the WorkScout-Core WordPress plugin that allows attackers to inject malicious scripts ...

Jan 22, 2026
CVE-2025-67964
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the favethemes Homey Core WordPress plugin. Attackers can inject malicious scripts via...

Jan 22, 2026
CVE-2025-67947
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the AdForest Elementor WordPress plugin. When users visit ...

Jan 22, 2026
CVE-2025-67949
7.1

This Cross-Site Scripting (XSS) vulnerability in the Hostiko WordPress theme allows attackers to inject malicious scripts into web pages viewed by oth...

Jan 22, 2026
CVE-2025-67952
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Grand Tour WordPress theme. When users visit a special...

Jan 22, 2026
CVE-2025-67943
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the My auctions allegro WordPress plugin. When users visit...

Jan 22, 2026
CVE-2025-67620
7.1

This reflected cross-site scripting (XSS) vulnerability in the CleverSoft Anon WordPress theme allows attackers to inject malicious scripts into web p...

Jan 22, 2026
CVE-2025-67923
7.1

This Cross-Site Scripting (XSS) vulnerability in the Crocoblock JetEngine WordPress plugin allows attackers to inject malicious scripts into web pages...

Jan 22, 2026
CVE-2025-67614
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the TheNa WordPress theme that allows attackers to inject malicious scripts into web p...

Jan 22, 2026
CVE-2025-68889
7.1

This vulnerability allows attackers to inject malicious scripts into Pinpoll WordPress plugin pages, which execute in victims' browsers when they visi...

Jan 8, 2026
CVE-2025-68891
7.1

This vulnerability allows attackers to inject malicious scripts into WordPress sites using the WP App Bar plugin. When users click specially crafted l...

Jan 8, 2026
CVE-2025-68873
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the PRIMER by chloédigital WordPress plugin. When users v...

Jan 8, 2026
CVE-2025-68874
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Visitor Stats Widget WordPress plugin. When users visi...

Jan 8, 2026
CVE-2025-68887
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP-BusinessDirectory WordPress plugin. When users visi...

Jan 8, 2026
CVE-2025-46494
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by WidgetKit Pro, a WordPress plugin. When users visit a spec...

Jan 7, 2026
CVE-2025-69082
7.1

This Cross-Site Scripting (XSS) vulnerability in the Frenify Arlo WordPress theme allows attackers to inject malicious scripts into web pages viewed b...

Jan 7, 2026
CVE-2025-32300
7.1

This vulnerability allows attackers to inject malicious scripts into DZS Video Gallery WordPress plugin pages, which execute in victims' browsers when...

Jan 7, 2026
CVE-2025-31642
7.1

This reflected cross-site scripting (XSS) vulnerability in the WPCHURCH WordPress plugin allows attackers to inject malicious scripts into web pages v...

Jan 7, 2026
CVE-2025-30631
7.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in two WordPress plugins. Attackers can inject malicious scripts via crafted U...

Jan 6, 2026
CVE-2025-69084
7.1

A reflected cross-site scripting (XSS) vulnerability in GT3 themes Photo Gallery WordPress plugin allows attackers to inject malicious scripts into we...

Jan 6, 2026
CVE-2025-69085
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the JobBank WordPress plugin, which are then executed in v...

Jan 6, 2026
CVE-2024-30547
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Header Image Slider WordPress plugin. When users visit...

Jan 6, 2026
CVE-2025-53235
7.1

This Cross-Site Scripting (XSS) vulnerability in the Easy Social WordPress plugin allows attackers to inject malicious scripts into web pages viewed b...

Dec 31, 2025
CVE-2025-47566
7.1

This vulnerability allows attackers to inject malicious scripts into ZoomSounds WordPress plugin pages, which execute in victims' browsers when they v...

Dec 31, 2025
CVE-2025-50053
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Blappsta Mobile App Plugin for WordPress. Attackers can inject malicious scripts v...

Dec 31, 2025
CVE-2025-52739
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Sala WordPress theme that allows attackers to inject malicious scripts into web pa...

Dec 31, 2025
CVE-2025-23705
7.1

This reflected cross-site scripting (XSS) vulnerability in the Zielke Design Project Gallery WordPress plugin allows attackers to inject malicious scr...

Dec 31, 2025
CVE-2025-23707
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Matamko En Masse WordPress plugin. When users visit a ...

Dec 31, 2025
CVE-2025-23719
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the ZhinaTwitterWidget WordPress plugin. When users visit ...

Dec 31, 2025
CVE-2025-23757
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the ZD Scribd iPaper WordPress plugin. When users visit a ...

Dec 31, 2025
CVE-2025-23667
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WordPress Custom Post Edit plugin. When users visit a ...

Dec 31, 2025
CVE-2025-23608
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the LIVE TV WordPress plugin. When users visit a specially...

Dec 31, 2025
CVE-2025-23458
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Ads24 Lite WordPress plugin. When users visit a specia...

Dec 30, 2025
CVE-2025-23469
7.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the Sleekplan WordPress plugin. Attackers can inject malicious scripts via ...

Dec 30, 2025
CVE-2025-23550
7.1

This reflected cross-site scripting (XSS) vulnerability in the WordPress Product Puller plugin allows attackers to inject malicious scripts into web p...

Dec 30, 2025
CVE-2025-23554
7.1

This reflected cross-site scripting (XSS) vulnerability in the Off Page SEO WordPress plugin allows attackers to inject malicious scripts into web pag...

Dec 30, 2025
CVE-2025-68878
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Advanced Custom CSS WordPress plugin. When users visit...

Dec 29, 2025
CVE-2025-68879
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Content Grid Slider WordPress plugin. When a user visi...

Dec 29, 2025
CVE-2025-68876
7.1

This reflected cross-site scripting (XSS) vulnerability in the Invelity SPS Connect WordPress plugin allows attackers to inject malicious scripts into...

Dec 29, 2025
CVE-2025-66118
7.1

This reflected cross-site scripting (XSS) vulnerability in the BoldGrid Sprout Clients WordPress plugin allows attackers to inject malicious scripts i...

Dec 18, 2025
CVE-2025-66119
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Bob Hostel WordPress plugin. When users visit a specia...

Dec 18, 2025
CVE-2025-6324
7.1

This DOM-based Cross-Site Scripting (XSS) vulnerability in the Easy Invoice WordPress plugin allows attackers to inject malicious scripts into web pag...

Dec 18, 2025
CVE-2025-66102
7.1

This Cross-Site Scripting (XSS) vulnerability in the FolioVision FV Antispam WordPress plugin allows attackers to inject malicious scripts into web pa...

Dec 18, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free