CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,803
Total CVEs
257
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
940
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,803)

CVE-2025-0447
8.8

This vulnerability in Google Chrome's navigation implementation allows attackers to escalate privileges through a crafted HTML page. It affects users ...

Jan 15, 2025
CVE-2024-9188
8.8

CVE-2024-9188 is a cross-site scripting vulnerability in Arista products that allows attackers to inject malicious scripts via specially crafted queri...

Jan 10, 2025
CVE-2024-54996
8.8

MonicaHQ v4.1.2 contains authenticated client-side injection vulnerabilities in the title and description parameters of the reminders creation feature...

Jan 10, 2025
CVE-2024-51229
8.8

This Cross-Site Scripting (XSS) vulnerability in LinZhaoguan pb-cms v2.0 allows remote attackers to inject malicious scripts via the theme management ...

Jan 9, 2025
CVE-2024-55074
8.8

This stored XSS vulnerability in Grocy's edit profile function allows attackers to upload malicious HTML or SVG files that execute arbitrary JavaScrip...

Jan 6, 2025
CVE-2024-47093
8.8

CVE-2024-47093 is a cross-site scripting (XSS) vulnerability in Nagvis versions before 1.9.42 due to improper input sanitization. Attackers can inject...

Dec 19, 2024
CVE-2024-51492
8.8

CVE-2024-51492 is a cross-site scripting (XSS) vulnerability in Zusam self-hosted forum software that allows attackers to execute arbitrary JavaScript...

Nov 1, 2024
CVE-2024-43684
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows attackers to trick authenticated users into performing uninten...

Oct 4, 2024
CVE-2024-38308
8.8

CVE-2024-38308 is a cross-site scripting (XSS) vulnerability in Advantech ADAM 5550's web application logs page that allows attackers to inject malici...

Sep 27, 2024
CVE-2024-2166
8.8

This is a reflected cross-site scripting (XSS) vulnerability in Forcepoint Email Security's Real Time Monitor modules. Attackers can inject malicious ...

Sep 4, 2024
CVE-2024-31199
8.8

CVE-2024-31199 is a persistent cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into web pages. This...

Jul 31, 2024
CVE-2024-41808
8.8

CVE-2024-41808 is a cross-site scripting (XSS) vulnerability in OpenObserve's dashboard filter selection menu that allows complete account takeover. A...

Jul 25, 2024
CVE-2024-3174
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt memory objects through specially crafted HTML pages, potentially leadi...

Jul 16, 2024
CVE-2024-40036
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...

Jul 9, 2024
CVE-2024-38521
8.8

Hush Line versions before 0.1.0 contain a stored cross-site scripting (XSS) vulnerability in the Inbox functionality. Attackers can inject malicious s...

Jun 28, 2024
CVE-2024-28983
8.8

This is a cross-site scripting (XSS) vulnerability in Hitachi Vantara Pentaho Business Analytics Server that allows attackers to inject malicious cont...

Jun 26, 2024
CVE-2024-34058
8.8

CVE-2024-34058 is a stored cross-site scripting (XSS) vulnerability in the WebTop package for NethServer 7 and 8. It allows attackers to inject malici...

May 17, 2024
CVE-2023-42034
8.8

This vulnerability in Visualware MyConnection Server allows remote attackers to bypass authentication via cross-site scripting (XSS) in the doRTAAcces...

May 3, 2024
CVE-2023-47626
8.8

This Cross-Site Scripting (XSS) vulnerability in iTop allows attackers to inject malicious scripts into the user's personal tokens display/edit interf...

Apr 15, 2024
CVE-2024-29022
8.8

This is a cross-site scripting (XSS) vulnerability in Xibo Digital Signage platform where unsanitized request headers allow attackers to inject malici...

Apr 12, 2024
CVE-2024-28671
8.8

DedeCMS v5.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /dede/stepselect_main.php endpoint. This allows attackers to trick auth...

Mar 13, 2024
CVE-2024-2247
8.8

This DOM-based cross-site scripting vulnerability in JFrog Artifactory allows attackers to inject malicious scripts that execute in users' browsers wh...

Mar 13, 2024
CVE-2024-28160
8.8

The Jenkins iceScrum Plugin 1.1.6 and earlier contains a stored cross-site scripting (XSS) vulnerability where iceScrum project URLs displayed on buil...

Mar 6, 2024
CVE-2024-21620
8.8

This is a cross-site scripting (XSS) vulnerability in Juniper Networks' J-Web interface for SRX and EX Series devices running Junos OS. An attacker ca...

Jan 25, 2024
CVE-2023-51063
8.8

This vulnerability allows attackers to inject malicious scripts into the QStar Archive Solutions web interface via the qnme-ajax?method=tree_level com...

Jan 13, 2024
CVE-2023-5880
8.8

This vulnerability allows attackers to inject malicious JavaScript or HTML into the web interface of Genie Aladdin Connect garage door openers when th...

Jan 3, 2024
CVE-2023-6790
8.8

This DOM-based XSS vulnerability in Palo Alto Networks PAN-OS allows attackers to execute malicious JavaScript in an administrator's browser by tricki...

Dec 13, 2023
CVE-2023-34446
8.8

This CVE describes a cross-site scripting (XSS) vulnerability in iTop's preferences.php page that allows attackers to inject malicious scripts into we...

Oct 25, 2023
CVE-2023-41895
8.8

This Cross-site Scripting (XSS) vulnerability in Home Assistant allows attackers to execute arbitrary JavaScript on the administration page by exploit...

Oct 19, 2023
CVE-2023-0829
8.8

This is a cross-site scripting (XSS) vulnerability in Plesk control panel versions 17.0 through 18.0.31. A malicious subscription owner can inject scr...

Sep 20, 2023
CVE-2023-39369
8.8

StarTrinity Softswitch version 2023-02-16 contains multiple reflected cross-site scripting (XSS) vulnerabilities that allow attackers to inject malici...

Sep 3, 2023
CVE-2023-4296
8.8

This is a cross-site scripting (XSS) vulnerability in PTC Codebeamer that allows attackers to inject and execute arbitrary JavaScript code in admin us...

Aug 29, 2023
CVE-2023-33159
8.8

CVE-2023-33159 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web...

Jul 11, 2023
CVE-2023-36389
8.8

A reflected cross-site scripting (XSS) vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to execute malicious JavaScript by tricking use...

Jul 11, 2023
CVE-2023-35971
8.8

This stored cross-site scripting vulnerability in ArubaOS web management interface allows unauthenticated attackers to inject malicious scripts that e...

Jul 5, 2023
CVE-2023-36345
8.8

A Cross-Site Request Forgery vulnerability in POS Codekop v2.0 allows attackers to trick authenticated users into performing unintended actions, poten...

Jun 23, 2023
CVE-2023-35155
8.8

This is a cross-site scripting (XSS) vulnerability in XWiki Platform that allows attackers to inject malicious JavaScript via specially crafted URLs. ...

Jun 23, 2023
CVE-2023-1031
8.8

MonicaHQ 4.0.0 contains a client-side template injection (CSTI) vulnerability in the settings endpoint's first_name parameter that allows authenticate...

May 8, 2023
CVE-2022-41330
8.8

This vulnerability allows unauthenticated attackers to execute cross-site scripting (XSS) attacks against Fortinet FortiOS and FortiProxy devices via ...

Apr 11, 2023
CVE-2022-43955
8.8

This vulnerability allows unauthenticated remote attackers to perform reflected cross-site scripting (XSS) attacks against FortiWeb web interfaces by ...

Apr 11, 2023
CVE-2022-2140
8.8

CVE-2022-2140 is a cross-site scripting (XSS) vulnerability in Elcomplus SmartICS v2.3.4.0 that allows authenticated users to inject malicious scripts...

Jun 27, 2022
CVE-2022-24814
8.8

This vulnerability allows attackers to execute arbitrary JavaScript in Directus by uploading HTML and JS files and embedding them in rich text fields....

Apr 4, 2022
CVE-2022-24384
8.8

This CVE describes a Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack that allows attackers to inject malicious scripts into web ...

Mar 14, 2022
CVE-2022-24386
8.8

This is a stored cross-site scripting (XSS) vulnerability in SmarterTools SmarterTrack customer service software. Attackers can inject malicious scrip...

Mar 14, 2022
CVE-2022-23013
8.8

This DOM-based cross-site scripting (XSS) vulnerability in BIG-IP DNS & GTM Configuration utility allows attackers to execute malicious JavaScript in ...

Jan 25, 2022
CVE-2021-44726
8.8

CVE-2021-44726 is a DOM-based cross-site scripting (XSS) vulnerability in KNIME Server's old WebPortal login page. It allows attackers to inject malic...

Dec 8, 2021
CVE-2021-43137
8.8

This vulnerability in hostel management system 2.1 allows attackers to perform Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) attack...

Dec 1, 2021
CVE-2021-24487
8.8

This vulnerability in the St-Daily-Tip WordPress plugin allows attackers to trick logged-in administrators into saving malicious JavaScript code in th...

Oct 25, 2021
CVE-2021-38466
8.8

This vulnerability allows attackers to inject malicious scripts via the help page of InHand Networks IR615 routers, which are then executed in victims...

Oct 19, 2021
CVE-2021-24581
8.8

This vulnerability in the Blue Admin WordPress plugin allows attackers to inject malicious scripts into the 'Logo Title' setting, which then executes ...

Aug 30, 2021

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,803 CVEs classified as CWE-79, with 257 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free