CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,786
Total CVEs
253
Critical
2,321
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
934
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,786)

CVE-2022-25069
9.6

Mark Text v0.16.3 contains a DOM-based cross-site scripting vulnerability in pasteCtrl.js that allows attackers to inject malicious scripts. When expl...

Mar 5, 2022
CVE-2022-21241
9.6

CVE-2022-21241 is a cross-site scripting vulnerability in CSV+ versions prior to 0.8.1 that allows remote unauthenticated attackers to inject maliciou...

Feb 8, 2022
CVE-2021-24814
9.6

This vulnerability in the WordPress GDPR plugin allows cross-site scripting (XSS) attacks through a misconfigured AJAX endpoint. Both unauthenticated ...

Feb 1, 2022
CVE-2022-22114
9.6

This is a reflected cross-site scripting (XSS) vulnerability in Teedy document management system that allows unauthenticated attackers to inject malic...

Jan 10, 2022
CVE-2015-20105
9.6

This vulnerability in the ClickBank Affiliate Ads WordPress plugin allows attackers to change plugin settings via CSRF attacks when an admin is logged...

Dec 2, 2021
CVE-2021-3994
9.6

CVE-2021-3994 is a cross-site scripting (XSS) vulnerability in django-helpdesk that allows attackers to inject malicious scripts into web pages viewed...

Dec 1, 2021
CVE-2021-43523
9.6

This vulnerability in uClibc and uClibc-ng allows DNS responses containing special characters to bypass validation, potentially leading to incorrect h...

Nov 10, 2021
CVE-2020-23718
9.6

This is a cross-site scripting (XSS) vulnerability in xujinliang zibbs 1.0 that allows attackers to inject malicious scripts via the route parameter i...

Nov 2, 2021
CVE-2020-23754
9.6

This is a Cross-Site Scripting (XSS) vulnerability in PHP-Fusion's poll administration feature that allows attackers to inject malicious scripts into ...

Nov 2, 2021
CVE-2021-24884
9.6

This vulnerability in the Formidable Form Builder WordPress plugin allows unauthenticated attackers to inject malicious HTML links containing JavaScri...

Oct 25, 2021
CVE-2021-23037
9.6

This is a reflected cross-site scripting (XSS) vulnerability in the BIG-IP Configuration utility that allows attackers to execute malicious JavaScript...

Sep 14, 2021
CVE-2021-22234
9.6

This vulnerability in GitLab allows attackers to read arbitrary files on the server by uploading a specially crafted design image. It affects all GitL...

Aug 5, 2021
CVE-2021-31761
9.6

CVE-2021-31761 is a reflected cross-site scripting (XSS) vulnerability in Webmin 1.973 that can be exploited to achieve remote command execution throu...

Apr 25, 2021
CVE-2021-28827
9.6

This vulnerability allows unauthenticated attackers to perform stored cross-site scripting (XSS) attacks against TIBCO administration systems by socia...

Apr 20, 2021
CVE-2021-29459
9.6

CVE-2021-29459 is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts into text fields. Bot...

Apr 20, 2021
CVE-2021-24228
9.6

This is a reflected cross-site scripting (XSS) vulnerability in the Patreon WordPress plugin that allows attackers to inject malicious scripts into th...

Apr 12, 2021
CVE-2021-29996
9.6

CVE-2021-29996 is a critical vulnerability in Mark Text that allows attackers to execute arbitrary commands through malicious .md files containing XSS...

Apr 5, 2021
CVE-2020-28149
9.6

CVE-2020-28149 is a cross-site scripting vulnerability in myDBR reporting software that allows attackers to inject malicious scripts via CSRF tokens. ...

Mar 15, 2021
CVE-2020-27224
9.6

CVE-2020-27224 is a critical vulnerability in Eclipse Theia's Markdown Preview component that allows cross-site scripting (XSS) to escalate to arbitra...

Feb 24, 2021
CVE-2021-3210
9.6

CVE-2021-3210 is a critical remote code execution vulnerability in BloodHound versions up to 4.0.1. Attackers can execute arbitrary system commands by...

Feb 19, 2021
CVE-2020-35125
9.6

This is a cross-site scripting (XSS) vulnerability in Mautic's forms component that allows attackers to inject malicious JavaScript via the mautic[ret...

Feb 9, 2021
CVE-2020-35124
9.6

This cross-site scripting (XSS) vulnerability in Mautic allows attackers to inject malicious JavaScript via the Referer header when downloading assets...

Jan 28, 2021
CVE-2020-5948
9.6

This vulnerability is a reflected Cross-Site Scripting (XSS) attack in the iControl REST interface of F5 BIG-IP devices. It allows attackers to execut...

Dec 11, 2020
CVE-2020-16608
9.6

CVE-2020-16608 is a cross-site scripting (XSS) vulnerability in Notable 1.8.4 that allows attackers to inject malicious Markdown content, which can le...

Dec 10, 2020
CVE-2020-18766
9.6

CVE-2020-18766 is a cross-site scripting vulnerability in AntSword v2.0.7 that allows remote attackers to execute arbitrary system commands. This affe...

Oct 26, 2020
CVE-2020-7750
9.6

CVE-2020-7750 is a DOM-based cross-site scripting (XSS) vulnerability in scratch-svg-renderer where improper SVG escaping allows attackers to inject a...

Oct 21, 2020
CVE-2020-26574
9.6

CVE-2020-26574 is a stored cross-site scripting (XSS) vulnerability in Leostream Connection Broker 8.2.x that allows unauthenticated attackers to inje...

Oct 6, 2020
CVE-2025-8668
9.4

This is a reflected cross-site scripting (XSS) vulnerability in Turboard software that allows attackers to inject malicious scripts into web pages. Us...

Feb 11, 2026
CVE-2023-4523
9.4

Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting (XSS), allowing attackers to inject and ...

Sep 27, 2023
CVE-2021-27442
9.4

This cross-site scripting vulnerability in Weintek cMT products allows unauthenticated remote attackers to inject malicious JavaScript code into web i...

May 16, 2022
CVE-2026-29183
9.3

An unauthenticated reflected XSS vulnerability in SiYuan's dynamic icon API allows attackers to inject malicious JavaScript via crafted SVG images. Wh...

Mar 6, 2026
CVE-2026-26266
9.3

A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to inject malicious JavaScript into emails sent to any Ali...

Mar 3, 2026
CVE-2026-27614
9.3

This is a stored cross-site scripting (XSS) vulnerability in Bugsink error tracking software. Unauthenticated attackers who can submit error events to...

Feb 25, 2026
CVE-2026-24399
9.3

This vulnerability allows attackers to inject malicious HTML/JavaScript payloads into ChatterMate chatbot inputs, which are then executed in users' br...

Jan 24, 2026
CVE-2026-21264
9.3

This cross-site scripting (XSS) vulnerability in Microsoft Account allows attackers to inject malicious scripts into web pages viewed by other users. ...

Jan 22, 2026
CVE-2026-21855
9.3

CVE-2026-21855 is a reflected Cross-Site Scripting (XSS) vulnerability in Tarkov Data Manager's toast notification system that allows attackers to exe...

Jan 7, 2026
CVE-2026-21430
9.3

CVE-2026-21430 is a CSRF vulnerability in Emlog's article creation functionality that allows attackers to force users to post malicious articles. When...

Jan 2, 2026
CVE-2025-64538
9.3

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...

Dec 10, 2025
CVE-2025-64539
9.3

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...

Dec 10, 2025
CVE-2025-64537
9.3

Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...

Dec 10, 2025
CVE-2025-49553
9.3

Adobe Connect versions 12.9 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute malicious JavaScript i...

Oct 14, 2025
CVE-2025-55321
9.3

This cross-site scripting (XSS) vulnerability in Azure Monitor allows attackers to inject malicious scripts into web pages, which execute when viewed ...

Oct 9, 2025
CVE-2025-6185
9.3

Leviton AcquiSuite and Energy Monitoring Hub have a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via URL...

Jul 18, 2025
CVE-2025-43567
9.3

Adobe Connect versions 12.8 and earlier contain a reflected Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts into...

May 13, 2025
CVE-2025-30223
9.3

A Cross-Site Scripting (XSS) vulnerability in Beego's RenderForm() function allows attackers to inject malicious JavaScript that executes in victims' ...

Mar 31, 2025
CVE-2025-24981
9.3

CVE-2025-24981 is a cross-site scripting (XSS) vulnerability in the MDC markdown parser that allows attackers to bypass URL filtering by encoding Java...

Feb 6, 2025
CVE-2024-57428
9.3

A stored cross-site scripting vulnerability in PHPJabbers Cinema Booking System v2.0 allows attackers to inject malicious JavaScript through file uplo...

Feb 6, 2025
CVE-2024-54032
9.3

Adobe Connect versions 12.6, 11.4.7 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts...

Dec 10, 2024
CVE-2024-54036
9.3

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to inject malicious JavaScript into vulnerable form fields. Whe...

Dec 10, 2024
CVE-2024-49038
9.3

This is a cross-site scripting (XSS) vulnerability in Microsoft Copilot Studio that allows an unauthorized attacker to inject malicious scripts into w...

Nov 26, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,786 CVEs classified as CWE-79, with 253 rated critical and 2,321 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free