CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,800
Total CVEs
256
Critical
2,327
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
940
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,800)

CVE-2023-40191
9.0

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts into the 'Blocke...

Feb 21, 2024
CVE-2024-25601
9.0

This stored cross-site scripting (XSS) vulnerability in Liferay's Expando module allows authenticated attackers to inject malicious scripts into geolo...

Feb 21, 2024
CVE-2024-23724
9.0

Ghost CMS versions up to 5.76.0 contain a stored cross-site scripting (XSS) vulnerability in SVG profile picture uploads. A contributor-level attacker...

Feb 11, 2024
CVE-2023-47861
9.0

A cross-site scripting vulnerability in WWBN AVideo's channelBody.php allows attackers to inject malicious JavaScript via user name input. When exploi...

Jan 10, 2024
CVE-2023-50982
9.0

This vulnerability in Stud.IP learning management system allows attackers to upload malicious files through cross-site scripting (XSS) due to insuffic...

Jan 8, 2024
CVE-2023-45869
9.0

This vulnerability allows any authenticated ILIAS user to execute arbitrary operating system commands when a privileged administrator account interact...

Oct 26, 2023
CVE-2023-45137
9.0

This is a stored cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious scripts into error messages when...

Oct 25, 2023
CVE-2023-45134
9.0

This is a stored cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers with user accounts to inject malicious JavaScript in...

Oct 25, 2023
CVE-2023-42628
9.0

This stored XSS vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into wiki pages through the content field. When other...

Oct 17, 2023
CVE-2023-44310
9.0

A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into page names. When users v...

Oct 17, 2023
CVE-2023-42629
9.0

This stored cross-site scripting (XSS) vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into vocabulary descriptions. ...

Oct 17, 2023
CVE-2023-32670
9.0

This is a Cross-Site Scripting (XSS) vulnerability in BuddyBoss platform version 2.2.9 that allows authenticated users with basic privileges to inject...

Oct 3, 2023
CVE-2023-39612
9.0

This cross-site scripting (XSS) vulnerability in FileBrowser allows authenticated attackers to escalate privileges to Administrator by tricking users ...

Sep 16, 2023
CVE-2023-40176
9.0

This stored XSS vulnerability in XWiki Platform allows any registered user to inject malicious JavaScript into their time zone preference, which execu...

Aug 23, 2023
CVE-2023-4203
9.0

This stored cross-site scripting (XSS) vulnerability in Advantech EKI-1524, EKI-1522, and EKI-1521 devices allows authenticated attackers to inject ma...

Aug 8, 2023
CVE-2023-36217
9.0

This Cross-Site Scripting (XSS) vulnerability in Xoops CMS allows remote attackers to inject malicious scripts via the category name field in the imag...

Aug 3, 2023
CVE-2023-30321
9.0

This CVE describes a Cross-Site Scripting (XSS) vulnerability in the textMessage field of the LoginServlet.java file in wliang6 ChatEngine. Attackers ...

Jul 6, 2023
CVE-2023-36477
9.0

This vulnerability allows any user with edit rights in XWiki Platform to edit all pages in the CKEditor space, enabling harmful actions like deleting ...

Jun 30, 2023
CVE-2023-35153
9.0

This stored cross-site scripting (XSS) vulnerability in XWiki Platform allows users with edit rights to inject malicious scripts into wiki pages. When...

Jun 23, 2023
CVE-2023-34464
9.0

This stored cross-site scripting (XSS) vulnerability in XWiki Platform allows users with document editing permissions to inject malicious HTML code. W...

Jun 23, 2023
CVE-2023-22582
9.0

This vulnerability allows attackers to inject malicious scripts into the Danfoss AK-EM100 web applications, which are then reflected back to users' br...

Jun 11, 2023
CVE-2023-22585
9.0

This vulnerability allows attackers to inject malicious scripts into the title parameter of Danfoss AK-EM100 web applications, which are then reflecte...

Jun 11, 2023
CVE-2023-3086
9.0

This stored cross-site scripting (XSS) vulnerability in TeamPass allows attackers to inject malicious scripts into the application, which are then exe...

Jun 3, 2023
CVE-2022-45938
9.0

This vulnerability allows attackers to inject malicious JavaScript into the Device ID field in Comcast's microeisbss inventory management system. When...

Jun 2, 2023
CVE-2023-31703
9.0

This vulnerability allows remote attackers to inject malicious JavaScript code via the 'from' parameter in the edit user form of the eScan management ...

May 17, 2023
CVE-2023-30627
9.0

A stored cross-site scripting (XSS) vulnerability in jellyfin-web allows attackers to make arbitrary REST API calls with admin privileges. When combin...

Apr 24, 2023
CVE-2023-29528
9.0

This vulnerability allows cross-site scripting (XSS) via invalid HTML comments in XWiki's restricted HTML cleaner mode. When exploited, it enables Jav...

Apr 20, 2023
CVE-2023-29201
9.0

This vulnerability allows cross-site scripting (XSS) attacks in XWiki Commons' HTML cleaner restricted mode, which insufficiently filtered dangerous H...

Apr 15, 2023
CVE-2021-33351
9.0

This is a cross-site scripting (XSS) vulnerability in the Wyomind Help Desk Magento 2 extension that allows attackers to inject malicious scripts into...

Mar 8, 2023
CVE-2023-0740
9.0

This stored cross-site scripting (XSS) vulnerability in the Answer software allows attackers to inject malicious scripts that execute in users' browse...

Feb 8, 2023
CVE-2023-0742
9.0

This stored cross-site scripting (XSS) vulnerability in the Answer software allows attackers to inject malicious scripts that execute when other users...

Feb 8, 2023
CVE-2022-48311
9.0

This CVE describes a cross-site scripting (XSS) vulnerability in HP Deskjet 2540 series printers that allows authenticated attackers to inject malicio...

Feb 6, 2023
CVE-2022-31035
9.0

CVE-2022-31035 is a cross-site scripting (XSS) vulnerability in Argo CD that allows attackers to inject malicious JavaScript links into the UI. When c...

Jun 27, 2022
CVE-2021-43932
9.0

CVE-2021-43932 is a cross-site scripting (XSS) vulnerability in Elcomplus SmartPTT SCADA software where attackers can inject malicious JavaScript into...

Apr 28, 2022
CVE-2022-28101
9.0

Turtlapp Turtle Note v0.7.2.6 has an HTML injection vulnerability where attackers can inject malicious <meta> tags during markdown parsing. This allow...

Apr 28, 2022
CVE-2022-28464
9.0

CVE-2022-28464 is a cross-site scripting (XSS) vulnerability in Apifox API development platform versions through 2.1.6 that allows attackers to inject...

Apr 27, 2022
CVE-2022-1344
9.0

This stored cross-site scripting (XSS) vulnerability in Organizr allows attackers to inject malicious scripts via filenames, which are then executed i...

Apr 13, 2022
CVE-2021-42136
9.0

A stored XSS vulnerability in REDCap's Missing Data Codes functionality allows attackers to inject malicious JavaScript that executes in users' browse...

Apr 13, 2022
CVE-2022-24123
9.0

CVE-2022-24123 is a critical vulnerability in MarkText that allows remote code execution through malicious markdown files. Attackers can craft .md fil...

Jan 29, 2022
CVE-2021-3985
9.0

CVE-2021-3985 is a cross-site scripting (XSS) vulnerability in Kimai2 time-tracking software that allows attackers to inject malicious scripts into we...

Dec 1, 2021
CVE-2021-43047
9.0

This CVE describes stored and reflected XSS vulnerabilities in TIBCO PartnerExpress that allow low-privileged attackers to inject malicious scripts. W...

Nov 16, 2021
CVE-2021-24693
9.0

This stored cross-site scripting (XSS) vulnerability in the Simple Download Monitor WordPress plugin allows users with Contributor role or higher to i...

Nov 8, 2021
CVE-2021-35493
9.0

This CVE describes stored and reflected cross-site scripting (XSS) vulnerabilities in TIBCO WebFOCUS components that allow low-privileged attackers to...

Sep 14, 2021
CVE-2021-25955
9.0

Dolibarr ERP CRM versions 2.8.1 to 13.0.2 contain a stored cross-site scripting (XSS) vulnerability in the WYSIWYG Editor module's Private Note field....

Aug 15, 2021
CVE-2020-27832
9.0

CVE-2020-27832 is a persistent cross-site scripting (XSS) vulnerability in Red Hat Quay that allows attackers to inject malicious scripts into reposit...

May 27, 2021
CVE-2020-35128
9.0

CVE-2020-35128 is a stored cross-site scripting (XSS) vulnerability in Mautic that allows attackers with company management permissions to inject mali...

Jan 19, 2021
CVE-2020-2503
9.0

This stored cross-site scripting (XSS) vulnerability in QNAP File Station allows remote attackers to inject malicious scripts that execute when users ...

Dec 24, 2020
CVE-2020-24445
9.0

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager allows attackers to inject malicious JavaScript into vulnerable form ...

Dec 10, 2020
CVE-2020-29071
9.0

This cross-site scripting (XSS) vulnerability in LiquidFiles allows attackers to execute malicious scripts when users access specially crafted HTML at...

Nov 25, 2020
CVE-2020-13169
9.0

This stored cross-site scripting (XSS) vulnerability in SolarWinds Orion Platform allows attackers to inject malicious scripts into multiple forms and...

Sep 17, 2020

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,800 CVEs classified as CWE-79, with 256 rated critical and 2,327 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free