CWE-79: Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Yearly Trend
Top Affected Vendors
All Cross-site Scripting (XSS) CVEs (8,800)
This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts into the 'Blocke...
Feb 21, 2024This stored cross-site scripting (XSS) vulnerability in Liferay's Expando module allows authenticated attackers to inject malicious scripts into geolo...
Feb 21, 2024Ghost CMS versions up to 5.76.0 contain a stored cross-site scripting (XSS) vulnerability in SVG profile picture uploads. A contributor-level attacker...
Feb 11, 2024A cross-site scripting vulnerability in WWBN AVideo's channelBody.php allows attackers to inject malicious JavaScript via user name input. When exploi...
Jan 10, 2024This vulnerability in Stud.IP learning management system allows attackers to upload malicious files through cross-site scripting (XSS) due to insuffic...
Jan 8, 2024This vulnerability allows any authenticated ILIAS user to execute arbitrary operating system commands when a privileged administrator account interact...
Oct 26, 2023This is a stored cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts into error messages when...
Oct 25, 2023This is a stored cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers with user accounts to inject malicious JavaScript in...
Oct 25, 2023This stored XSS vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into wiki pages through the content field. When other...
Oct 17, 2023A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into page names. When users v...
Oct 17, 2023This stored cross-site scripting (XSS) vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into vocabulary descriptions. ...
Oct 17, 2023This is a Cross-Site Scripting (XSS) vulnerability in BuddyBoss platform version 2.2.9 that allows authenticated users with basic privileges to inject...
Oct 3, 2023This cross-site scripting (XSS) vulnerability in FileBrowser allows authenticated attackers to escalate privileges to Administrator by tricking users ...
Sep 16, 2023This stored XSS vulnerability in XWiki Platform allows any registered user to inject malicious JavaScript into their time zone preference, which execu...
Aug 23, 2023This stored cross-site scripting (XSS) vulnerability in Advantech EKI-1524, EKI-1522, and EKI-1521 devices allows authenticated attackers to inject ma...
Aug 8, 2023This Cross-Site Scripting (XSS) vulnerability in Xoops CMS allows remote attackers to inject malicious scripts via the category name field in the imag...
Aug 3, 2023This CVE describes a Cross-Site Scripting (XSS) vulnerability in the textMessage field of the LoginServlet.java file in wliang6 ChatEngine. Attackers ...
Jul 6, 2023This vulnerability allows any user with edit rights in XWiki Platform to edit all pages in the CKEditor space, enabling harmful actions like deleting ...
Jun 30, 2023This stored cross-site scripting (XSS) vulnerability in XWiki Platform allows users with edit rights to inject malicious scripts into wiki pages. When...
Jun 23, 2023This stored cross-site scripting (XSS) vulnerability in XWiki Platform allows users with document editing permissions to inject malicious HTML code. W...
Jun 23, 2023This vulnerability allows attackers to inject malicious scripts into the Danfoss AK-EM100 web applications, which are then reflected back to users' br...
Jun 11, 2023This vulnerability allows attackers to inject malicious scripts into the title parameter of Danfoss AK-EM100 web applications, which are then reflecte...
Jun 11, 2023This stored cross-site scripting (XSS) vulnerability in TeamPass allows attackers to inject malicious scripts into the application, which are then exe...
Jun 3, 2023This vulnerability allows attackers to inject malicious JavaScript into the Device ID field in Comcast's microeisbss inventory management system. When...
Jun 2, 2023This vulnerability allows remote attackers to inject malicious JavaScript code via the 'from' parameter in the edit user form of the eScan management ...
May 17, 2023A stored cross-site scripting (XSS) vulnerability in jellyfin-web allows attackers to make arbitrary REST API calls with admin privileges. When combin...
Apr 24, 2023This vulnerability allows cross-site scripting (XSS) via invalid HTML comments in XWiki's restricted HTML cleaner mode. When exploited, it enables Jav...
Apr 20, 2023This vulnerability allows cross-site scripting (XSS) attacks in XWiki Commons' HTML cleaner restricted mode, which insufficiently filtered dangerous H...
Apr 15, 2023This is a cross-site scripting (XSS) vulnerability in the Wyomind Help Desk Magento 2 extension that allows attackers to inject malicious scripts into...
Mar 8, 2023This stored cross-site scripting (XSS) vulnerability in the Answer software allows attackers to inject malicious scripts that execute in users' browse...
Feb 8, 2023This stored cross-site scripting (XSS) vulnerability in the Answer software allows attackers to inject malicious scripts that execute when other users...
Feb 8, 2023This CVE describes a cross-site scripting (XSS) vulnerability in HP Deskjet 2540 series printers that allows authenticated attackers to inject malicio...
Feb 6, 2023CVE-2022-31035 is a cross-site scripting (XSS) vulnerability in Argo CD that allows attackers to inject malicious JavaScript links into the UI. When c...
Jun 27, 2022CVE-2021-43932 is a cross-site scripting (XSS) vulnerability in Elcomplus SmartPTT SCADA software where attackers can inject malicious JavaScript into...
Apr 28, 2022Turtlapp Turtle Note v0.7.2.6 has an HTML injection vulnerability where attackers can inject malicious <meta> tags during markdown parsing. This allow...
Apr 28, 2022CVE-2022-28464 is a cross-site scripting (XSS) vulnerability in Apifox API development platform versions through 2.1.6 that allows attackers to inject...
Apr 27, 2022This stored cross-site scripting (XSS) vulnerability in Organizr allows attackers to inject malicious scripts via filenames, which are then executed i...
Apr 13, 2022A stored XSS vulnerability in REDCap's Missing Data Codes functionality allows attackers to inject malicious JavaScript that executes in users' browse...
Apr 13, 2022CVE-2022-24123 is a critical vulnerability in MarkText that allows remote code execution through malicious markdown files. Attackers can craft .md fil...
Jan 29, 2022CVE-2021-3985 is a cross-site scripting (XSS) vulnerability in Kimai2 time-tracking software that allows attackers to inject malicious scripts into we...
Dec 1, 2021This CVE describes stored and reflected XSS vulnerabilities in TIBCO PartnerExpress that allow low-privileged attackers to inject malicious scripts. W...
Nov 16, 2021This stored cross-site scripting (XSS) vulnerability in the Simple Download Monitor WordPress plugin allows users with Contributor role or higher to i...
Nov 8, 2021This CVE describes stored and reflected cross-site scripting (XSS) vulnerabilities in TIBCO WebFOCUS components that allow low-privileged attackers to...
Sep 14, 2021Dolibarr ERP CRM versions 2.8.1 to 13.0.2 contain a stored cross-site scripting (XSS) vulnerability in the WYSIWYG Editor module's Private Note field....
Aug 15, 2021CVE-2020-27832 is a persistent cross-site scripting (XSS) vulnerability in Red Hat Quay that allows attackers to inject malicious scripts into reposit...
May 27, 2021CVE-2020-35128 is a stored cross-site scripting (XSS) vulnerability in Mautic that allows attackers with company management permissions to inject mali...
Jan 19, 2021This stored cross-site scripting (XSS) vulnerability in QNAP File Station allows remote attackers to inject malicious scripts that execute when users ...
Dec 24, 2020This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form ...
Dec 10, 2020This cross-site scripting (XSS) vulnerability in LiquidFiles allows attackers to execute malicious scripts when users access specially crafted HTML at...
Nov 25, 2020This stored cross-site scripting (XSS) vulnerability in SolarWinds Orion Platform allows attackers to inject malicious scripts into multiple forms and...
Sep 17, 2020About Cross-site Scripting (XSS) (CWE-79)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.
Our database tracks 8,800 CVEs classified as CWE-79, with 256 rated critical and 2,327 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.
External reference: View CWE-79 on MITRE CWE →
Monitor Cross-site Scripting (XSS) Vulnerabilities
Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.
Start Monitoring Free