CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,795
Total CVEs
254
Critical
2,324
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
940
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,795)

CVE-2024-49038
9.3

This is a cross-site scripting (XSS) vulnerability in Microsoft Copilot Studio that allows an unauthorized attacker to inject malicious scripts into w...

Nov 26, 2024
CVE-2024-38108
9.3

This is a spoofing vulnerability in Azure Stack Hub that allows attackers to inject malicious content into web applications, potentially tricking user...

Aug 13, 2024
CVE-2024-42008
9.3

A Cross-Site Scripting vulnerability in Roundcube webmail allows attackers to steal and send victims' emails via malicious email attachments with dang...

Aug 5, 2024
CVE-2024-23786
9.3

A cross-site scripting (XSS) vulnerability in Sharp Energy Management Controller with Cloud Services allows network-adjacent unauthenticated attackers...

Feb 14, 2024
CVE-2024-1143
9.3

Central Dogma versions before 0.64.1 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pag...

Feb 2, 2024
CVE-2023-44393
9.3

A reflected XSS vulnerability in Piwigo's admin interface allows attackers to inject malicious JavaScript via crafted URLs. Only authenticated adminis...

Oct 9, 2023
CVE-2023-2507
9.3

This vulnerability in CleverTap Cordova Plugin allows remote attackers to execute arbitrary JavaScript code in applications that open specially crafte...

Jul 15, 2023
CVE-2023-36459
9.3

This vulnerability allows attackers to inject arbitrary HTML into Mastodon oEmbed preview cards by bypassing HTML sanitization. When users click on ma...

Jul 6, 2023
CVE-2021-32989
9.3

This reflected cross-site scripting (XSS) vulnerability in LAquis SCADA allows attackers to inject malicious scripts via error messages when requestin...

May 25, 2022
CVE-2021-41161
9.3

This vulnerability allows attackers to inject malicious JavaScript into CSV files exported from Combodo iTop. When users open these CSV files, the Jav...

Apr 21, 2022
CVE-2021-43409
9.3

The WPO365 | LOGIN WordPress plugin (versions up to 15.3) has a stored XSS vulnerability where anonymous users can inject malicious scripts. When a Wo...

Nov 19, 2021
CVE-2020-15231
9.3

This vulnerability in mapfish-print allows attackers to exploit JSONP support to execute cross-site scripting (XSS) attacks. Users of mapfish-print ve...

Oct 2, 2020
CVE-2026-24838
9.1

This vulnerability allows attackers to inject malicious scripts into DNN module titles, which execute in users' browsers when viewing affected pages. ...

Jan 28, 2026
CVE-2026-23722
9.1

This is a reflected cross-site scripting (XSS) vulnerability in WeGIA web management software that allows unauthenticated attackers to inject maliciou...

Jan 16, 2026
CVE-2023-48082
9.1

Nagios XI versions before 2024R1 have an API key generation vulnerability where attackers can generate identical API keys for all users. This allows a...

Oct 14, 2024
CVE-2024-4180
9.1

This vulnerability in The Events Calendar WordPress plugin allows attackers to inject malicious scripts into web pages viewed by other users. It affec...

Jun 4, 2024
CVE-2024-26517
9.1

This SQL injection vulnerability in School Task Manager v1.0 allows remote attackers to execute arbitrary SQL commands via the delete-task.php compone...

May 14, 2024
CVE-2023-49785
9.1

CVE-2023-49785 is a server-side request forgery (SSRF) and cross-site scripting (XSS) vulnerability in NextChat (ChatGPT-Next-Web) that allows attacke...

Mar 12, 2024
CVE-2024-20719
9.1

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows an authenticated admin attacker to inject malicious JavaScript into admi...

Feb 15, 2024
CVE-2022-25784
9.1

This cross-site scripting (XSS) vulnerability in Secomea SiteManager's web GUI allows authenticated users to inject malicious scripts. When exploited,...

May 4, 2022
CVE-2025-59542
9.0

A stored cross-site scripting (XSS) vulnerability in Chamilo LMS allows low-privileged users (like trainers) to inject malicious JavaScript into cours...

Mar 6, 2026
CVE-2025-55208
9.0

This vulnerability allows low-privilege users in Chamilo LMS to upload malicious files containing stored XSS payloads through the Social Networks feat...

Mar 5, 2026
CVE-2026-27822
9.0

A stored cross-site scripting (XSS) vulnerability in RustFS Console allows attackers to inject malicious JavaScript that executes when administrators ...

Feb 25, 2026
CVE-2025-68723
9.0

Axigen Mail Server versions before 10.5.57 contain multiple stored XSS vulnerabilities in the WebAdmin interface. Attackers can inject malicious JavaS...

Feb 5, 2026
CVE-2026-24769
9.0

Authenticated users can upload malicious SVG files containing JavaScript in NocoDB versions before 0.301.0. When other users view these attachments, t...

Jan 28, 2026
CVE-2026-1009
9.0

A stored cross-site scripting vulnerability in Altium Forum allows authenticated attackers to inject malicious JavaScript into forum posts. When other...

Jan 15, 2026
CVE-2025-65267
9.0

This vulnerability allows attackers to upload malicious SVG avatar images containing JavaScript payloads in ERPNext and Frappe Framework. When an admi...

Dec 3, 2025
CVE-2025-64325
9.0

This vulnerability allows an attacker to inject malicious content into the Emby Server admin dashboard by manipulating the X-Emby-Client header during...

Nov 18, 2025
CVE-2025-64338
9.0

ClipBucket v5 versions 5.5.2-#156 and below contain a stored cross-site scripting (XSS) vulnerability in the photo collection name field. Authenticate...

Nov 7, 2025
CVE-2025-59978
9.0

This stored XSS vulnerability in Juniper Networks Junos Space allows attackers to inject malicious scripts into web pages that execute with administra...

Oct 9, 2025
CVE-2025-56795
9.0

CVE-2025-56795 is a stored cross-site scripting vulnerability in Mealie recipe management software. Attackers can inject malicious scripts into recipe...

Sep 29, 2025
CVE-2025-59545
9.0

This vulnerability in DNN's Prompt module allows attackers to execute arbitrary scripts through malicious input, leading to cross-site scripting (XSS)...

Sep 23, 2025
CVE-2025-54117
9.0

A stored cross-site scripting (XSS) vulnerability in NamelessMC's dashboard text editor allows authenticated attackers to inject malicious scripts tha...

Aug 18, 2025
CVE-2025-53835
9.0

This vulnerability in XWiki Rendering allows cross-site scripting (XSS) attacks through raw HTML blocks in the XHTML syntax. Users who can edit docume...

Jul 14, 2025
CVE-2025-47933
9.0

This vulnerability allows attackers to perform cross-site scripting (XSS) attacks in Argo CD's repository page. Attackers with repository edit permiss...

May 29, 2025
CVE-2024-56156
9.0

This vulnerability in Halo website building software allows attackers to bypass file upload validation controls. Attackers can upload malicious files ...

Apr 25, 2025
CVE-2024-8017
9.0

A cross-site scripting (XSS) vulnerability in open-webui versions up to 0.3.8 allows attackers to inject malicious scripts into tooltips. When exploit...

Mar 20, 2025
CVE-2024-7053
9.0

This vulnerability allows an attacker with a user-level account to perform a session fixation attack in open-webui/open-webui version 0.3.8. By embedd...

Mar 20, 2025
CVE-2024-39272
9.0

A cross-site scripting vulnerability in ClearML Enterprise Server's dataset upload functionality allows attackers to inject malicious HTML/JavaScript ...

Feb 6, 2025
CVE-2024-55227
9.0

This CVE describes a cross-site scripting (XSS) vulnerability in Dolibarr's Events/Agenda module that allows attackers to inject malicious scripts int...

Jan 27, 2025
CVE-2024-54142
9.0

This vulnerability allows cross-site scripting (XSS) attacks in Discourse AI plugin when HTML entities from shared bot conversations leak into Discour...

Jan 14, 2025
CVE-2024-6581
9.0

This vulnerability in Lollms v9.9 allows attackers to upload malicious SVG files that bypass incomplete sanitization, leading to cross-site scripting ...

Oct 29, 2024
CVE-2024-45856
9.0

A stored cross-site scripting (XSS) vulnerability in MindsDB allows attackers to inject malicious JavaScript into ML Engine, database, project, or dat...

Sep 12, 2024
CVE-2024-42366
9.0

CVE-2024-42366 is a critical vulnerability in VRCX, a companion application for VRChat, that allows remote command execution through a combination of ...

Aug 8, 2024
CVE-2024-31401
9.0

This is a cross-site scripting (XSS) vulnerability in Cybozu Garoon that allows authenticated administrators to inject malicious scripts into web page...

Jun 11, 2024
CVE-2023-38121
9.0

This is a cross-site scripting (XSS) vulnerability in Inductive Automation Ignition's OPC UA Quick Client web interface that allows remote code execut...

May 3, 2024
CVE-2024-2692
9.0

CVE-2024-2692 is a Server-Side Cross-Site Scripting (XSS) vulnerability in SiYuan note-taking software version 3.0.3 that allows attackers to execute ...

Apr 4, 2024
CVE-2023-47795
9.0

This stored XSS vulnerability allows authenticated attackers to inject malicious scripts into document titles in Liferay's Document and Media widget. ...

Feb 21, 2024
CVE-2024-26266
9.0

This CVE describes multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP. Authenticated attackers can inject malicious ...

Feb 21, 2024
CVE-2023-40191
9.0

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts into the 'Blocke...

Feb 21, 2024

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,795 CVEs classified as CWE-79, with 254 rated critical and 2,324 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free