CWE-79 · 47,649 records
Cross-site scripting
Why does it happen?
User content is inserted into the page as HTML. The browser interprets the content as code rather than data.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
commentEl.innerHTML = comment.body;Fixed
commentEl.textContent = comment.body;How to prevent it
- 01Insert user content as text, or encode it for its context.
- 02If HTML is required, pass it through a trusted sanitizer.
- 03Add a second layer of defense with a Content Security Policy header.
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-3929Weaponized | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Critical9.8 | KEV | 99.0% | Apr 30, 2019 |
92Now | CVE-2024-42009Weaponized | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails ofroundcube · webmail · CWE-79 | Critical9.3 | KEV | 82.9% | Aug 5, 2024 |
89Now | CVE-2023-34192Weaponized | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scrsynacor · zimbra collaboration suite · CWE-79 | Critical9.0 | KEV | 77.3% | Jul 6, 2023 |
82Now | CVE-2019-18426Weaponized | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-swhatsapp · whatsapp · CWE-79 | High8.2 | KEV | 67.9% | Jan 21, 2020 |
80Now | CVE-2020-3580Weaponized | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilitiescisco · secure firewall threat defense · CWE-79 | Medium6.1 | KEV | 85.6% | Oct 21, 2020 |
79This week | CVE-2020-11023Weaponized | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Medium6.1 | KEV | 84.9% | Apr 29, 2020 |
77This week | CVE-2020-13965Weaponized | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 76.6% | Jun 8, 2020 |
76This week | CVE-2024-37383Weaponized | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 73.3% | Jun 7, 2024 |
76This week | CVE-2019-9978Weaponized | The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameterwarfareplugins · social warfare · CWE-79 | Medium6.1 | KEV | 72.9% | Mar 24, 2019 |
76This week | CVE-2024-43573Weaponized | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-79 | High8.1 | KEV | 46.1% | Oct 8, 2024 |
74This week | CVE-2023-5631Weaponized | Stored XSS vulnerability in Roundcuberoundcube · webmail · CWE-79 | Medium5.4 | KEV | 75.9% | Oct 18, 2023 |
73This week | CVE-2023-43770Weaponized | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of roundcube · webmail · CWE-79 | Medium6.1 | KEV | 63.7% | Sep 22, 2023 |
69This week | CVE-2023-37580Weaponized | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.synacor · zimbra collaboration suite · CWE-79 | Medium6.1 | KEV | 49.1% | Jul 31, 2023 |
68This week | CVE-2022-39197Weaponized | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTMhelpsystems · cobalt strike · CWE-79 | Medium6.1 | KEV | 46.4% | Sep 21, 2022 |
66This week | CVE-2013-5223Weaponized | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.dlink · dsl-2760u firmware · CWE-79 | Medium5.4 | KEV | 50.8% | Nov 19, 2013 |
65This week | CVE-2021-26829Weaponized | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.scadabr · scadabr · CWE-79 | Medium5.4 | KEV | 48.1% | Jun 11, 2021 |
64This week | CVE-2023-49785Proof of concept | NextChat vulnerable to Server-Side Request Forgery and Cross-site Scriptingnextchat · nextchat · CWE-79 | Critical9.8 | — | 83.2% | Mar 11, 2024 |
64This week | CVE-2022-28368Weaponized | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (withdompdf project · dompdf · CWE-79 | Critical9.8 | — | 82.4% | Apr 2, 2022 |
64This week | CVE-2020-35730Weaponized | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 32.7% | Dec 28, 2020 |
63This week | CVE-2018-6882Weaponized | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 synacor · zimbra collaboration suite · CWE-79 | Medium6.1 | KEV | 29.8% | Mar 27, 2018 |
63This week | CVE-2018-19953Weaponized | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Medium6.1 | KEV | 28.8% | Oct 28, 2020 |
62This week | CVE-2025-68461Weaponized | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG droundcube · webmail · CWE-79 | Medium6.1 | KEV | 26.8% | Dec 18, 2025 |
62This week | CVE-2024-44309Weaponized | A cookie management issue was addressed with improved state management.debian · debian linux · CWE-79 | Medium6.3 | KEV | 22.6% | Nov 19, 2024 |
61This week | CVE-2024-27443Weaponized | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.zimbra · collaboration · CWE-79 | Medium6.1 | KEV | 23.6% | Aug 12, 2024 |
61This week | CVE-2014-2120Weaponized | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackercisco · adaptive security appliance software · CWE-79 | Medium6.1 | KEV | 22.6% | Mar 18, 2014 |
- CVE-2019-392999Now
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%crestron · am-100 firmwareApr 30, 2019
- CVE-2024-4200992Now
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of
CriticalCVSS 9.3KEVWeaponizedEPSS 83%roundcube · webmailAug 5, 2024
- CVE-2023-3419289Now
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr
CriticalCVSS 9.0KEVWeaponizedEPSS 77%synacor · zimbra collaboration suiteJul 6, 2023
- CVE-2019-1842682Now
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s
HighCVSS 8.2KEVWeaponizedEPSS 68%whatsapp · whatsappJan 21, 2020
- CVE-2020-358080Now
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
MediumCVSS 6.1KEVWeaponizedEPSS 86%cisco · secure firewall threat defenseOct 21, 2020
- CVE-2020-1102379This week
Potential XSS vulnerability in jQuery
MediumCVSS 6.1KEVWeaponizedEPSS 85%jquery · jqueryApr 29, 2020
- CVE-2020-1396577This week
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
MediumCVSS 6.1KEVWeaponizedEPSS 77%roundcube · webmailJun 8, 2020
- CVE-2024-3738376This week
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
MediumCVSS 6.1KEVWeaponizedEPSS 73%roundcube · webmailJun 7, 2024
- CVE-2019-997876This week
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter
MediumCVSS 6.1KEVWeaponizedEPSS 73%warfareplugins · social warfareMar 24, 2019
- CVE-2024-4357376This week
Windows MSHTML Platform Spoofing Vulnerability
HighCVSS 8.1KEVWeaponizedEPSS 46%microsoft · windows 10 1507Oct 8, 2024
- CVE-2023-563174This week
Stored XSS vulnerability in Roundcube
MediumCVSS 5.4KEVWeaponizedEPSS 76%roundcube · webmailOct 18, 2023
- CVE-2023-4377073This week
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of
MediumCVSS 6.1KEVWeaponizedEPSS 64%roundcube · webmailSep 22, 2023
- CVE-2023-3758069This week
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
MediumCVSS 6.1KEVWeaponizedEPSS 49%synacor · zimbra collaboration suiteJul 31, 2023
- CVE-2022-3919768This week
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM
MediumCVSS 6.1KEVWeaponizedEPSS 46%helpsystems · cobalt strikeSep 21, 2022
- CVE-2013-522366This week
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.
MediumCVSS 5.4KEVWeaponizedEPSS 51%dlink · dsl-2760u firmwareNov 19, 2013
- CVE-2021-2682965This week
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
MediumCVSS 5.4KEVWeaponizedEPSS 48%scadabr · scadabrJun 11, 2021
- CVE-2023-4978564This week
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
CriticalCVSS 9.8Proof of conceptEPSS 83%nextchat · nextchatMar 11, 2024
- CVE-2022-2836864This week
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with
CriticalCVSS 9.8WeaponizedEPSS 82%dompdf project · dompdfApr 2, 2022
- CVE-2020-3573064This week
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.
MediumCVSS 6.1KEVWeaponizedEPSS 33%roundcube · webmailDec 28, 2020
- CVE-2018-688263This week
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7
MediumCVSS 6.1KEVWeaponizedEPSS 30%synacor · zimbra collaboration suiteMar 27, 2018
- CVE-2018-1995363This week
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
MediumCVSS 6.1KEVWeaponizedEPSS 29%qnap · qtsOct 28, 2020
- CVE-2025-6846162This week
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d
MediumCVSS 6.1KEVWeaponizedEPSS 27%roundcube · webmailDec 18, 2025
- CVE-2024-4430962This week
A cookie management issue was addressed with improved state management.
MediumCVSS 6.3KEVWeaponizedEPSS 23%debian · debian linuxNov 19, 2024
- CVE-2024-2744361This week
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
MediumCVSS 6.1KEVWeaponizedEPSS 24%zimbra · collaborationAug 12, 2024
- CVE-2014-212061This week
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attacker
MediumCVSS 6.1KEVWeaponizedEPSS 23%cisco · adaptive security appliance softwareMar 18, 2014