Skip to content
Noroxi

CWE-79 · 47,649 records

Cross-site scripting

Why does it happen?

User content is inserted into the page as HTML. The browser interprets the content as code rather than data.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
commentEl.innerHTML = comment.body;

Fixed

ts
commentEl.textContent = comment.body;

How to prevent it

  1. 01Insert user content as text, or encode it for its context.
  2. 02If HTML is required, pass it through a trusted sanitizer.
  3. 03Add a second layer of defense with a Content Security Policy header.

CVEs in this class

10,000 records

  • The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    crestron · am-100 firmwareApr 30, 2019

  • A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of

    CriticalCVSS 9.3KEVWeaponizedEPSS 83%

    roundcube · webmailAug 5, 2024

  • Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr

    CriticalCVSS 9.0KEVWeaponizedEPSS 77%

    synacor · zimbra collaboration suiteJul 6, 2023

  • A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s

    HighCVSS 8.2KEVWeaponizedEPSS 68%

    whatsapp · whatsappJan 21, 2020

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities

    MediumCVSS 6.1KEVWeaponizedEPSS 86%

    cisco · secure firewall threat defenseOct 21, 2020

  • CVE-2020-11023
    79This week

    Potential XSS vulnerability in jQuery

    MediumCVSS 6.1KEVWeaponizedEPSS 85%

    jquery · jqueryApr 29, 2020

  • CVE-2020-13965
    77This week

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.

    MediumCVSS 6.1KEVWeaponizedEPSS 77%

    roundcube · webmailJun 8, 2020

  • CVE-2024-37383
    76This week

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    MediumCVSS 6.1KEVWeaponizedEPSS 73%

    roundcube · webmailJun 7, 2024

  • CVE-2019-9978
    76This week

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter

    MediumCVSS 6.1KEVWeaponizedEPSS 73%

    warfareplugins · social warfareMar 24, 2019

  • CVE-2024-43573
    76This week

    Windows MSHTML Platform Spoofing Vulnerability

    HighCVSS 8.1KEVWeaponizedEPSS 46%

    microsoft · windows 10 1507Oct 8, 2024

  • CVE-2023-5631
    74This week

    Stored XSS vulnerability in Roundcube

    MediumCVSS 5.4KEVWeaponizedEPSS 76%

    roundcube · webmailOct 18, 2023

  • CVE-2023-43770
    73This week

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of

    MediumCVSS 6.1KEVWeaponizedEPSS 64%

    roundcube · webmailSep 22, 2023

  • CVE-2023-37580
    69This week

    Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

    MediumCVSS 6.1KEVWeaponizedEPSS 49%

    synacor · zimbra collaboration suiteJul 31, 2023

  • CVE-2022-39197
    68This week

    An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM

    MediumCVSS 6.1KEVWeaponizedEPSS 46%

    helpsystems · cobalt strikeSep 21, 2022

  • CVE-2013-5223
    66This week

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.

    MediumCVSS 5.4KEVWeaponizedEPSS 51%

    dlink · dsl-2760u firmwareNov 19, 2013

  • CVE-2021-26829
    65This week

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

    MediumCVSS 5.4KEVWeaponizedEPSS 48%

    scadabr · scadabrJun 11, 2021

  • CVE-2023-49785
    64This week

    NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting

    CriticalCVSS 9.8Proof of conceptEPSS 83%

    nextchat · nextchatMar 11, 2024

  • CVE-2022-28368
    64This week

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with

    CriticalCVSS 9.8WeaponizedEPSS 82%

    dompdf project · dompdfApr 2, 2022

  • CVE-2020-35730
    64This week

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.

    MediumCVSS 6.1KEVWeaponizedEPSS 33%

    roundcube · webmailDec 28, 2020

  • CVE-2018-6882
    63This week

    Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7

    MediumCVSS 6.1KEVWeaponizedEPSS 30%

    synacor · zimbra collaboration suiteMar 27, 2018

  • CVE-2018-19953
    63This week

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

    MediumCVSS 6.1KEVWeaponizedEPSS 29%

    qnap · qtsOct 28, 2020

  • CVE-2025-68461
    62This week

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d

    MediumCVSS 6.1KEVWeaponizedEPSS 27%

    roundcube · webmailDec 18, 2025

  • CVE-2024-44309
    62This week

    A cookie management issue was addressed with improved state management.

    MediumCVSS 6.3KEVWeaponizedEPSS 23%

    debian · debian linuxNov 19, 2024

  • CVE-2024-27443
    61This week

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.

    MediumCVSS 6.1KEVWeaponizedEPSS 24%

    zimbra · collaborationAug 12, 2024

  • CVE-2014-2120
    61This week

    Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attacker

    MediumCVSS 6.1KEVWeaponizedEPSS 23%

    cisco · adaptive security appliance softwareMar 18, 2014

All vulnerability classes