CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,805
Total CVEs
259
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,805)

CVE-2021-38466
8.8

This vulnerability allows attackers to inject malicious scripts via the help page of InHand Networks IR615 routers, which are then executed in victims...

Oct 19, 2021
CVE-2021-24581
8.8

This vulnerability in the Blue Admin WordPress plugin allows attackers to inject malicious scripts into the 'Logo Title' setting, which then executes ...

Aug 30, 2021
CVE-2021-3693
8.8

This is a cross-site scripting (XSS) vulnerability in LedgerSMB that allows attackers to inject malicious HTML fragments into the DOM. When exploited,...

Aug 23, 2021
CVE-2021-24565
8.8

This vulnerability in the Contact Form 7 Captcha WordPress plugin allows attackers to change plugin settings without user consent via CSRF attacks, an...

Aug 23, 2021
CVE-2020-4520
8.8

This vulnerability allows remote attackers to inject malicious HTML code into IBM Cognos Analytics. When authenticated users view the compromised cont...

Jun 1, 2021
CVE-2021-20994
8.8

This is a cross-site scripting (XSS) vulnerability in WAGO managed switches that allows attackers to inject malicious code into the web-based manageme...

May 13, 2021
CVE-2021-0275
8.8

This is a cross-site scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web interface that allows an attacker to hijack another user's activ...

Apr 22, 2021
CVE-2026-28683
8.7

This vulnerability allows authenticated attackers to upload malicious SVG files and create hotlinks that execute stored cross-site scripting (XSS) att...

Mar 6, 2026
CVE-2026-26022
8.7

This stored XSS vulnerability in Gogs allows authenticated users to inject malicious JavaScript via data: URIs in comments and issue descriptions. The...

Mar 5, 2026
CVE-2025-69231
8.7

A stored cross-site scripting vulnerability in OpenEMR's GAD-7 anxiety assessment form allows authenticated clinicians to inject malicious JavaScript....

Feb 25, 2026
CVE-2026-25648
8.7

Authenticated users in Traccar GPS tracking system can upload malicious SVG files containing JavaScript, which executes in other users' browsers when ...

Feb 23, 2026
CVE-2026-25759
8.7

A stored cross-site scripting (XSS) vulnerability in Statmatic CMS allows authenticated users with content creation permissions to inject malicious Ja...

Feb 11, 2026
CVE-2026-24665
8.7

Authenticated students can inject malicious JavaScript into uploaded assignment files in Open eClass platform. When instructors view these submissions...

Feb 3, 2026
CVE-2026-23625
8.7

OpenProject versions 16.3.0 through 16.6.4 have a stored cross-site scripting vulnerability in the Roadmap view that allows attackers to inject malici...

Jan 19, 2026
CVE-2026-0695
8.7

This is a stored cross-site scripting (XSS) vulnerability in ConnectWise PSA's Time Entry Audit Trail feature. Attackers can inject malicious scripts ...

Jan 16, 2026
CVE-2026-22867
8.7

LaSuite Doc versions 3.8.0 to 4.3.0 contain a stored XSS vulnerability in the Interlinking feature. Attackers with document editing privileges can inj...

Jan 15, 2026
CVE-2025-9222
8.7

This vulnerability allows an authenticated user to inject malicious scripts into GitLab's Markdown rendering, which then executes in other users' brow...

Jan 9, 2026
CVE-2025-63611
8.7

This stored cross-site scripting (XSS) vulnerability in phpgurukul Hostel Management System v2.1 allows attackers to inject malicious scripts into com...

Jan 8, 2026
CVE-2025-66824
8.7

A stored XSS vulnerability in TrueConf Server v5.5.2.10813 allows attackers to inject malicious scripts via the meeting location field. When users vie...

Dec 30, 2025
CVE-2025-12716
8.7

This vulnerability allows authenticated GitLab users to perform unauthorized actions on behalf of other users by creating wiki pages with malicious co...

Dec 11, 2025
CVE-2025-12956
8.7

A reflected Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts into web ...

Dec 8, 2025
CVE-2025-65959
8.7

A stored cross-site scripting (XSS) vulnerability in Open WebUI allows authenticated users to upload malicious Markdown files containing SVG tags that...

Dec 4, 2025
CVE-2025-10555
8.7

A stored XSS vulnerability in DELMIA Service Process Engineer allows attackers to inject malicious scripts into Service Items Management pages. When u...

Nov 24, 2025
CVE-2025-10554
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Product Manager allows attackers to inject malicious scripts that execute in users' browse...

Nov 24, 2025
CVE-2025-62210
8.7

This cross-site scripting (XSS) vulnerability in Dynamics 365 Field Service allows authenticated attackers to inject malicious scripts into web pages....

Nov 11, 2025
CVE-2025-62211
8.7

This cross-site scripting (XSS) vulnerability in Dynamics 365 Field Service allows authenticated attackers to inject malicious scripts into web pages....

Nov 11, 2025
CVE-2025-64495
8.7

Open WebUI versions 0.6.34 and below contain a DOM-based cross-site scripting (XSS) vulnerability in the custom prompt insertion feature. When 'Insert...

Nov 8, 2025
CVE-2025-60503
8.7

This cross-site scripting vulnerability in UltimatePOS 4.8 allows authenticated attackers to inject malicious JavaScript into the admin log panel. Whe...

Nov 3, 2025
CVE-2025-10557
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts into issue m...

Oct 13, 2025
CVE-2025-10552
8.7

A stored Cross-site Scripting (XSS) vulnerability in 3DSwym within 3DSwymer on Release 3DEXPERIENCE R2025x allows attackers to inject malicious script...

Oct 13, 2025
CVE-2025-25018
8.7

This vulnerability in Kibana allows attackers to inject malicious scripts into web pages through improper input neutralization, leading to stored cros...

Oct 10, 2025
CVE-2025-9642
8.7

This is a cross-site scripting (XSS) vulnerability in GitLab that allows attackers to inject malicious content, potentially leading to account takeove...

Sep 26, 2025
CVE-2025-10244
8.7

A stored cross-site scripting vulnerability in Autodesk Fusion allows malicious HTML payloads to execute arbitrary code when rendered by the applicati...

Sep 23, 2025
CVE-2025-57731
8.7

This stored cross-site scripting (XSS) vulnerability in JetBrains YouTrack allows attackers to inject malicious scripts into Mermaid diagram content t...

Aug 20, 2025
CVE-2025-52478
8.7

A stored Cross-Site Scripting (XSS) vulnerability in n8n's Form Trigger node allows authenticated attackers to inject malicious HTML/JavaScript. This ...

Aug 19, 2025
CVE-2025-4700
8.7

This vulnerability in GitLab allows attackers to inject malicious scripts that execute in users' browsers when viewing specially crafted content, lead...

Jul 23, 2025
CVE-2025-6948
8.7

This CVE describes a cross-site scripting (XSS) vulnerability in GitLab that allows attackers to inject malicious content. Under certain conditions, s...

Jul 10, 2025
CVE-2025-2443
8.7

This vulnerability in GitLab EE allows attackers to execute malicious JavaScript in users' browsers through cross-site scripting (XSS) attacks while b...

Jun 20, 2025
CVE-2025-2254
8.7

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers through GitLab's snippet viewer functionality. It affects ...

Jun 12, 2025
CVE-2025-4985
8.7

A stored Cross-site Scripting (XSS) vulnerability in Dassault Systèmes 3DEXPERIENCE Project Portfolio Manager allows attackers to inject malicious sc...

May 30, 2025
CVE-2025-4988
8.7

A stored Cross-site Scripting (XSS) vulnerability in Dassault Systèmes' 3DEXPERIENCE platform allows attackers to inject malicious scripts into Resul...

May 30, 2025
CVE-2025-4990
8.7

A stored Cross-site Scripting (XSS) vulnerability in Dassault Systèmes 3DEXPERIENCE Product Manager's Change Governance component allows attackers to...

May 30, 2025
CVE-2025-4992
8.7

A stored Cross-site Scripting (XSS) vulnerability in Service Items Management within Service Process Engineer allows attackers to inject malicious scr...

May 30, 2025
CVE-2025-4983
8.7

A stored Cross-site Scripting (XSS) vulnerability in City Referential Manager on 3DEXPERIENCE R2025x allows attackers to inject malicious scripts that...

May 30, 2025
CVE-2025-0602
8.7

A stored Cross-site Scripting (XSS) vulnerability in the Compare feature of Collaborative Industry Innovator within 3DEXPERIENCE allows attackers to i...

May 30, 2025
CVE-2025-1763
8.7

This vulnerability in GitLab EE allows attackers to execute malicious scripts in users' browsers by bypassing Content Security Policy protections. It ...

May 30, 2025
CVE-2025-0811
8.7

This cross-site scripting vulnerability in GitLab allows attackers to inject malicious scripts through improperly rendered file types. When exploited,...

Mar 27, 2025
CVE-2025-2255
8.7

This vulnerability allows Cross-Site Scripting (XSS) attacks through error messages in GitLab's AppSec feature. Attackers can inject malicious scripts...

Mar 27, 2025
CVE-2025-0828
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Product Engineering Specialist allows attackers to inject malicious scripts that execute i...

Mar 17, 2025
CVE-2025-0829
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's 3D Markup feature allows attackers to inject malicious ...

Mar 17, 2025

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,805 CVEs classified as CWE-79, with 259 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free