CWE-79: Cross-site Scripting (XSS)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

8,805
Total CVEs
259
Critical
2,329
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
941
2025
4,799
2024
2,396
2023
455
2022
70

Top Affected Vendors

1 Adobe 349
2 Ibm 78
3 Liferay 65
4 Microsoft 58
5 Nagios 45
6 Phpgurukul 44
7 Wegia 39
8 Gitlab 38
9 Cisco 38
10 Esri 34

All Cross-site Scripting (XSS) CVEs (8,805)

CVE-2025-0830
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Change Manager's Meeting Management component allows attackers to inject malicious scripts...

Mar 17, 2025
CVE-2025-0832
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's Project Gantt feature allows attackers to inject malici...

Mar 17, 2025
CVE-2025-0595
8.7

A stored Cross-site Scripting (XSS) vulnerability in 3DDashboard within 3DSwymer allows attackers to inject malicious scripts that execute in users' b...

Mar 17, 2025
CVE-2025-0596
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's Bookmark Editor allows attackers to inject malicious sc...

Mar 17, 2025
CVE-2025-0598
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts into the Rel...

Mar 17, 2025
CVE-2025-0599
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's Document Management allows attackers to inject maliciou...

Mar 17, 2025
CVE-2025-0600
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's Product Explorer allows attackers to inject malicious s...

Mar 17, 2025
CVE-2025-0601
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts into issue m...

Mar 17, 2025
CVE-2025-0826
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator's 3D Navigate component allows attackers to inject malici...

Mar 17, 2025
CVE-2025-0827
8.7

A stored Cross-site Scripting (XSS) vulnerability in 3DPlay within 3DSwymer allows attackers to inject malicious scripts that execute in users' browse...

Mar 17, 2025
CVE-2025-0475
8.7

A cross-site scripting (XSS) vulnerability in GitLab's proxy feature allows attackers to inject malicious scripts that execute in users' browsers when...

Mar 3, 2025
CVE-2025-0376
8.7

A cross-site scripting (XSS) vulnerability in GitLab CE/EE allows attackers to inject malicious scripts into change pages. When exploited, this enable...

Feb 12, 2025
CVE-2025-24438
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2025-24416
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2025-24417
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious scripts into form fields. When...

Feb 11, 2025
CVE-2025-24410
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2025-24412
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2025-24413
8.7

A stored cross-site scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious scripts into vulnerable form f...

Feb 11, 2025
CVE-2025-24414
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2025-24415
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable for...

Feb 11, 2025
CVE-2024-10383
8.7

This vulnerability allows cross-site scripting (XSS) attacks when loading .ipynb files in GitLab's web IDE. Attackers can execute arbitrary JavaScript...

Feb 7, 2025
CVE-2025-0314
8.7

This vulnerability allows attackers to inject malicious scripts through improperly rendered file types in GitLab, leading to cross-site scripting (XSS...

Jan 24, 2025
CVE-2024-12090
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator on 3DEXPERIENCE R2024x allows attackers to inject malicio...

Dec 16, 2024
CVE-2024-12092
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator on 3DEXPERIENCE R2024x allows attackers to inject malicio...

Dec 16, 2024
CVE-2024-51093
8.7

A stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT v7.0.13 allows attackers to upload malicious XML files containing JavaScript. When execu...

Nov 12, 2024
CVE-2024-8312
8.7

This vulnerability allows attackers to inject malicious HTML into GitLab's Global Search field on diff views, leading to cross-site scripting (XSS). A...

Oct 24, 2024
CVE-2024-6380
8.7

A reflected Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts into web ...

Oct 16, 2024
CVE-2024-7737
8.7

A stored Cross-site Scripting (XSS) vulnerability in 3DSwym component of 3DSwymer allows attackers to inject malicious scripts that execute in users' ...

Sep 19, 2024
CVE-2024-7938
8.7

A stored Cross-site Scripting (XSS) vulnerability in 3DDashboard within 3DSwymer allows attackers to inject malicious scripts that execute in users' b...

Sep 2, 2024
CVE-2024-8004
8.7

A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows attackers to inject malicious scripts that execute...

Sep 2, 2024
CVE-2024-41819
8.7

Note Mark versions before 0.13.1 contain a stored cross-site scripting (XSS) vulnerability where attackers can inject malicious JavaScript into markdo...

Jul 29, 2024
CVE-2024-21686
8.7

This is a stored cross-site scripting (XSS) vulnerability in Confluence Data Center and Server that allows authenticated attackers to inject malicious...

Jul 16, 2024
CVE-2024-4901
8.7

A stored cross-site scripting (XSS) vulnerability in GitLab allows attackers to inject malicious JavaScript into commit notes, which then executes in ...

Jun 27, 2024
CVE-2024-3110
8.7

A stored XSS vulnerability in anything-llm allows attackers with manager role to inject malicious JavaScript via crafted URLs. When an admin clicks th...

Jun 6, 2024
CVE-2024-3594
8.7

The IDonate WordPress plugin through version 1.9.0 contains a stored cross-site scripting (XSS) vulnerability in its settings. This allows authenticat...

May 23, 2024
CVE-2024-2835
8.7

A stored cross-site scripting vulnerability in OpenText ArcSight Enterprise Security Manager and ArcSight Platform allows attackers to inject maliciou...

May 20, 2024
CVE-2023-47123
8.7

This Cross-Site Scripting (XSS) vulnerability in iTop allows attackers to inject malicious scripts into object friendlyname/complementary name fields....

Apr 15, 2024
CVE-2024-2279
8.7

This vulnerability is a stored cross-site scripting (XSS) flaw in GitLab's autocomplete feature for issue references, affecting GitLab CE/EE versions ...

Apr 12, 2024
CVE-2023-6033
8.7

This cross-site scripting (XSS) vulnerability in GitLab's Jira integration configuration allows attackers to inject malicious JavaScript that executes...

Dec 1, 2023
CVE-2023-26222
8.7

This vulnerability allows attackers with low privileges and network access to execute stored cross-site scripting (XSS) attacks in TIBCO EBX web appli...

Nov 14, 2023
CVE-2023-46238
8.7

This vulnerability in ZITADEL allows attackers to inject malicious JavaScript into SVG avatar images, potentially enabling account takeover when victi...

Oct 26, 2023
CVE-2021-42083
8.7

This vulnerability in OSNexus QuantaStor allows authenticated attackers to create alerts with malicious webhook URLs that execute arbitrary commands a...

Jul 10, 2023
CVE-2023-2442
8.7

This stored cross-site scripting (XSS) vulnerability in GitLab allows attackers to inject malicious scripts into merge requests. When victims view the...

Jun 7, 2023
CVE-2023-3083
8.7

This stored cross-site scripting (XSS) vulnerability in TeamPass allows attackers to inject malicious scripts that execute when other users view affec...

Jun 3, 2023
CVE-2023-34088
8.7

A stored cross-site scripting (XSS) vulnerability in Collabora Online allows attackers to create documents with malicious names containing JavaScript ...

May 31, 2023
CVE-2023-31223
8.7

Dradis versions before 4.8.0 contain a persistent cross-site scripting (XSS) vulnerability in avatar handling that allows authenticated author users t...

Apr 25, 2023
CVE-2023-0050
8.7

This vulnerability allows attackers to inject malicious scripts through specially crafted Kroki diagrams in GitLab, leading to stored cross-site scrip...

Mar 9, 2023
CVE-2022-41566
8.7

This vulnerability allows attackers with low privileges and network access to execute stored cross-site scripting (XSS) attacks on TIBCO EBX Add-ons s...

Feb 22, 2023
CVE-2023-22932
8.7

This vulnerability allows attackers to inject malicious scripts into Splunk Web views through Base64-encoded image error messages. When exploited, it ...

Feb 14, 2023
CVE-2022-30999
8.7

This vulnerability allows attackers to execute arbitrary JavaScript code by uploading malicious SVG files to FoF Upload extension for Flarum forums. A...

Jun 2, 2022

About Cross-site Scripting (XSS) (CWE-79)

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page served to other users.

Our database tracks 8,805 CVEs classified as CWE-79, with 259 rated critical and 2,329 rated high severity. The average CVSS score for Cross-site Scripting (XSS) vulnerabilities is 6.4.

External reference: View CWE-79 on MITRE CWE →

Monitor Cross-site Scripting (XSS) Vulnerabilities

Get alerted when new Cross-site Scripting (XSS) CVEs affect your infrastructure.

Start Monitoring Free