CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,786)
Mark Text v0.16.3 contains a DOM-based cross-site scripting vulnerability in pasteCtrl.js that allows attackers to inject malicious scripts. When expl...
Mar 5, 2022CVE-2022-21241 is a cross-site scripting vulnerability in CSV+ versions prior to 0.8.1 that allows remote unauthenticated attackers to inject maliciou...
Feb 8, 2022This vulnerability in the WordPress GDPR plugin allows cross-site scripting (XSS) attacks through a misconfigured AJAX endpoint. Both unauthenticated ...
Feb 1, 2022This is a reflected cross-site scripting (XSS) vulnerability in Teedy document management system that allows unauthenticated attackers to inject malic...
Jan 10, 2022This vulnerability in the ClickBank Affiliate Ads WordPress plugin allows attackers to change plugin settings via CSRF attacks when an admin is logged...
Dec 2, 2021CVE-2021-3994 is a cross-site scripting (XSS) vulnerability in django-helpdesk that allows attackers to inject malicious scripts into web pages viewed...
Dec 1, 2021This vulnerability in uClibc and uClibc-ng allows DNS responses containing special characters to bypass validation, potentially leading to incorrect h...
Nov 10, 2021This is a cross-site scripting (XSS) vulnerability in xujinliang zibbs 1.0 that allows attackers to inject malicious scripts via the route parameter i...
Nov 2, 2021This is a Cross-Site Scripting (XSS) vulnerability in PHP-Fusion's poll administration feature that allows attackers to inject malicious scripts into ...
Nov 2, 2021This vulnerability in the Formidable Form Builder WordPress plugin allows unauthenticated attackers to inject malicious HTML links containing JavaScri...
Oct 25, 2021This is a reflected cross-site scripting (XSS) vulnerability in the BIG-IP Configuration utility that allows attackers to execute malicious JavaScript...
Sep 14, 2021This vulnerability in GitLab allows attackers to read arbitrary files on the server by uploading a specially crafted design image. It affects all GitL...
Aug 5, 2021CVE-2021-31761 is a reflected cross-site scripting (XSS) vulnerability in Webmin 1.973 that can be exploited to achieve remote command execution throu...
Apr 25, 2021This vulnerability allows unauthenticated attackers to perform stored cross-site scripting (XSS) attacks against TIBCO administration systems by socia...
Apr 20, 2021CVE-2021-29459 is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts into text fields. Bot...
Apr 20, 2021This is a reflected cross-site scripting (XSS) vulnerability in the Patreon WordPress plugin that allows attackers to inject malicious scripts into th...
Apr 12, 2021CVE-2021-29996 is a critical vulnerability in Mark Text that allows attackers to execute arbitrary commands through malicious .md files containing XSS...
Apr 5, 2021CVE-2020-28149 is a cross-site scripting vulnerability in myDBR reporting software that allows attackers to inject malicious scripts via CSRF tokens. ...
Mar 15, 2021CVE-2020-27224 is a critical vulnerability in Eclipse Theia's Markdown Preview component that allows cross-site scripting (XSS) to escalate to arbitra...
Feb 24, 2021CVE-2021-3210 is a critical remote code execution vulnerability in BloodHound versions up to 4.0.1. Attackers can execute arbitrary system commands by...
Feb 19, 2021This is a cross-site scripting (XSS) vulnerability in Mautic's forms component that allows attackers to inject malicious JavaScript via the mautic[ret...
Feb 9, 2021This cross-site scripting (XSS) vulnerability in Mautic allows attackers to inject malicious JavaScript via the Referer header when downloading assets...
Jan 28, 2021This vulnerability is a reflected Cross-Site Scripting (XSS) attack in the iControl REST interface of F5 BIG-IP devices. It allows attackers to execut...
Dec 11, 2020CVE-2020-16608 is a cross-site scripting (XSS) vulnerability in Notable 1.8.4 that allows attackers to inject malicious Markdown content, which can le...
Dec 10, 2020CVE-2020-18766 is a cross-site scripting vulnerability in AntSword v2.0.7 that allows remote attackers to execute arbitrary system commands. This affe...
Oct 26, 2020CVE-2020-7750 is a DOM-based cross-site scripting (XSS) vulnerability in scratch-svg-renderer where improper SVG escaping allows attackers to inject a...
Oct 21, 2020CVE-2020-26574 is a stored cross-site scripting (XSS) vulnerability in Leostream Connection Broker 8.2.x that allows unauthenticated attackers to inje...
Oct 6, 2020This is a reflected cross-site scripting (XSS) vulnerability in Turboard software that allows attackers to inject malicious scripts into web pages. Us...
Feb 11, 2026Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting (XSS), allowing attackers to inject and ...
Sep 27, 2023This cross-site scripting vulnerability in Weintek cMT products allows unauthenticated remote attackers to inject malicious JavaScript code into web i...
May 16, 2022An unauthenticated reflected XSS vulnerability in SiYuan's dynamic icon API allows attackers to inject malicious JavaScript via crafted SVG images. Wh...
Mar 6, 2026A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to inject malicious JavaScript into emails sent to any Ali...
Mar 3, 2026This is a stored cross-site scripting (XSS) vulnerability in Bugsink error tracking software. Unauthenticated attackers who can submit error events to...
Feb 25, 2026This vulnerability allows attackers to inject malicious HTML/JavaScript payloads into ChatterMate chatbot inputs, which are then executed in users' br...
Jan 24, 2026This cross-site scripting (XSS) vulnerability in Microsoft Account allows attackers to inject malicious scripts into web pages viewed by other users. ...
Jan 22, 2026CVE-2026-21855 is a reflected Cross-Site Scripting (XSS) vulnerability in Tarkov Data Manager's toast notification system that allows attackers to exe...
Jan 7, 2026CVE-2026-21430 is a CSRF vulnerability in Emlog's article creation functionality that allows attackers to force users to post malicious articles. When...
Jan 2, 2026Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...
Dec 10, 2025Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...
Dec 10, 2025Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute arbitrary...
Dec 10, 2025Adobe Connect versions 12.9 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute malicious JavaScript i...
Oct 14, 2025This cross-site scripting (XSS) vulnerability in Azure Monitor allows attackers to inject malicious scripts into web pages, which execute when viewed ...
Oct 9, 2025Leviton AcquiSuite and Energy Monitoring Hub have a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via URL...
Jul 18, 2025Adobe Connect versions 12.8 and earlier contain a reflected Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts into...
May 13, 2025A Cross-Site Scripting (XSS) vulnerability in Beego's RenderForm() function allows attackers to inject malicious JavaScript that executes in victims' ...
Mar 31, 2025CVE-2025-24981 is a cross-site scripting (XSS) vulnerability in the MDC markdown parser that allows attackers to bypass URL filtering by encoding Java...
Feb 6, 2025A stored cross-site scripting vulnerability in PHPJabbers Cinema Booking System v2.0 allows attackers to inject malicious JavaScript through file uplo...
Feb 6, 2025Adobe Connect versions 12.6, 11.4.7 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts...
Dec 10, 2024This stored Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to inject malicious JavaScript into vulnerable form fields. Whe...
Dec 10, 2024This is a cross-site scripting (XSS) vulnerability in Microsoft Copilot Studio that allows an unauthorized attacker to inject malicious scripts into w...
Nov 26, 2024About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,786 CVEs classified as CWE-79, with 253 rated critical and 2,321 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free