CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,870
Total CVEs
275
Critical
2,378
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 60
5 Nagios 45
6 Phpgurukul 44
7 Gitlab 40
8 Wegia 39
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,870)

CVE-2025-64372
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Traveler WordPress theme that allows attackers to inject malicious scripts into we...

Dec 18, 2025
CVE-2025-64376
7.1

This Cross-Site Scripting (XSS) vulnerability in the ListingPro WordPress theme allows attackers to inject malicious scripts into web pages viewed by ...

Dec 18, 2025
CVE-2025-64260
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the ANAC XML Bandi di Gara WordPress plugin. When users vi...

Dec 18, 2025
CVE-2025-64207
7.1

This DOM-based cross-site scripting (XSS) vulnerability in the Jannah WordPress theme allows attackers to inject malicious scripts into web pages view...

Dec 18, 2025
CVE-2025-64217
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Photography WordPress theme. When users visit a specia...

Dec 18, 2025
CVE-2025-64221
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the dt-reservation-plugin WordPress plugin. When users vis...

Dec 18, 2025
CVE-2025-64189
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the XStore Core WordPress plugin. Attackers can inject malicious scripts via crafted U...

Dec 18, 2025
CVE-2025-64191
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the XStore WordPress theme, which are then executed in vic...

Dec 18, 2025
CVE-2025-64203
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Mailster WordPress plugin that allows attackers to inject malicious scripts into w...

Dec 18, 2025
CVE-2025-60182
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Schiocco Support Board WordPress plugin. Attackers can inject malicious scripts in...

Dec 18, 2025
CVE-2025-57897
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Logtik WordPress theme that allows attackers to inject malicious scripts into web ...

Dec 18, 2025
CVE-2025-14701
7.1

A stored cross-site scripting (XSS) vulnerability in Crafty Controller's Server MOTD component allows remote unauthenticated attackers to inject malic...

Dec 17, 2025
CVE-2025-67648
7.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in Shopware's login page. Attackers can inject malicious JavaScript via the wa...

Dec 11, 2025
CVE-2025-67541
7.1

This stored Cross-Site Scripting (XSS) vulnerability in the WP-ShowHide WordPress plugin allows attackers to inject malicious scripts into web pages t...

Dec 9, 2025
CVE-2025-41748
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_Dot1xCfg.php allows attackers to trick authenticated users into clicking malicious ...

Dec 9, 2025
CVE-2025-41749
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in port_util.php allows attackers to trick authenticated users into clicking malicious lin...

Dec 9, 2025
CVE-2025-41750
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_PortCfg.php allows attackers to trick authenticated users into clicking malicious l...

Dec 9, 2025
CVE-2025-41751
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portCntr.php allows attackers to trick authenticated users into clicking malicious ...

Dec 9, 2025
CVE-2025-41752
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portSfp.php allows attackers to trick authenticated users into clicking malicious l...

Dec 9, 2025
CVE-2025-41745
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portCntr2.php allows attackers to trick authenticated users into sending malicious ...

Dec 9, 2025
CVE-2025-41746
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portSecCfg.php allows attackers to trick authenticated users into sending malicious...

Dec 9, 2025
CVE-2025-41747
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_vlanIntfCfg.php allows attackers to trick authenticated users into sending maliciou...

Dec 9, 2025
CVE-2025-41695
7.1

An unauthenticated cross-site scripting (XSS) vulnerability in dyn_conn.php allows attackers to trick authenticated users into sending malicious POST ...

Dec 9, 2025
CVE-2025-13071
7.1

This vulnerability allows attackers to inject malicious scripts into WordPress admin pages via unsanitized parameters in the Custom Admin Menu plugin....

Dec 9, 2025
CVE-2025-13159
7.1

The Flo Forms WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript via an AJAX endpoint. When adminis...

Nov 21, 2025
CVE-2025-64167
7.1

This vulnerability allows attackers to inject malicious JavaScript via the URL parameter in Combodo iTop's export.php file, leading to cross-site scri...

Nov 10, 2025
CVE-2025-63588
7.1

An unauthenticated reflected cross-site scripting vulnerability in CMSimpleXH allows attackers to inject malicious JavaScript via crafted requests lik...

Nov 6, 2025
CVE-2025-63589
7.1

This reflected XSS vulnerability in CMSimple_XH 1.8 allows attackers to inject malicious JavaScript via URL path segments, which gets executed in vict...

Nov 6, 2025
CVE-2025-64224
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Grand Conference Theme Custom Post Type plugin for Wor...

Nov 6, 2025
CVE-2025-62076
7.1

This Cross-Site Scripting (XSS) vulnerability in the WordPress Simple Payment plugin allows attackers to inject malicious scripts into web pages viewe...

Nov 6, 2025
CVE-2025-64196
7.1

This reflected cross-site scripting (XSS) vulnerability in the Booster for WooCommerce plugin allows attackers to inject malicious scripts into web pa...

Nov 6, 2025
CVE-2025-62057
7.1

This is a cross-site scripting (XSS) vulnerability in the Houzez WordPress theme functionality plugin that allows attackers to inject malicious script...

Nov 6, 2025
CVE-2025-62074
7.1

This Cross-Site Scripting (XSS) vulnerability in the WPMobile.App WordPress plugin allows attackers to inject malicious scripts into web pages viewed ...

Nov 6, 2025
CVE-2025-62040
7.1

This is a cross-site scripting (XSS) vulnerability in the YOP Poll WordPress plugin that allows attackers to inject malicious scripts into web pages. ...

Nov 6, 2025
CVE-2025-62031
7.1

This is a cross-site scripting (XSS) vulnerability in the tagDiv Composer WordPress plugin that allows attackers to inject malicious scripts into web ...

Nov 6, 2025
CVE-2025-62036
7.1

This is a cross-site scripting (XSS) vulnerability in the Togo WordPress theme that allows attackers to inject malicious scripts into web pages. Attac...

Nov 6, 2025
CVE-2025-59556
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the GoStore WordPress theme that allows attackers to inject malicious scripts into web...

Nov 6, 2025
CVE-2025-58638
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Institutions Directory WordPress plugin. When users vi...

Nov 6, 2025
CVE-2025-58964
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Enzy WordPress theme that allows attackers to inject malicious scripts into web pa...

Nov 6, 2025
CVE-2025-54721
7.1

This Cross-Site Scripting (XSS) vulnerability in the ThimPress Resca WordPress theme allows attackers to inject malicious scripts into web pages that ...

Nov 6, 2025
CVE-2025-54722
7.1

This vulnerability allows attackers to inject malicious scripts into WooTour plugin pages, which execute in victims' browsers when they visit speciall...

Nov 6, 2025
CVE-2025-54737
7.1

This reflected cross-site scripting (XSS) vulnerability in the Jobmonster WordPress theme allows attackers to inject malicious scripts into web pages ...

Nov 6, 2025
CVE-2025-53585
7.1

This is a reflected cross-site scripting (XSS) vulnerability in the NooTheme WeMusic WordPress theme. Attackers can inject malicious scripts via craft...

Nov 6, 2025
CVE-2025-54718
7.1

This reflected cross-site scripting (XSS) vulnerability in the NooTheme Yogi WordPress theme allows attackers to inject malicious scripts into web pag...

Nov 6, 2025
CVE-2025-53573
7.1

This Cross-Site Scripting (XSS) vulnerability in the Epic Review WordPress plugin allows attackers to inject malicious scripts into web pages viewed b...

Nov 6, 2025
CVE-2025-43338
7.1

This vulnerability allows attackers to cause denial of service or memory corruption by tricking users into opening malicious media files. It affects m...

Nov 4, 2025
CVE-2025-10280
7.1

This vulnerability allows cross-site scripting (XSS) attacks in SailPoint IdentityIQ when web services return non-HTML content with an incorrect HTML ...

Nov 3, 2025
CVE-2025-62020
7.1

This Cross-Site Scripting (XSS) vulnerability in the Infomaniak VOD WordPress plugin allows attackers to inject malicious scripts into web pages. When...

Oct 22, 2025
CVE-2025-59004
7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WC Return products WordPress plugin. When users visit ...

Oct 22, 2025
CVE-2025-52742
7.1

This Cross-site Scripting (XSS) vulnerability in the WordPress Pets plugin allows attackers to inject malicious scripts into web pages viewed by other...

Oct 22, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,870 CVEs classified as CWE-79, with 275 rated critical and 2,378 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free