CWE-79— Cross-site Scripting (XSS)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.— MITRE CWE catalog
47,883 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-79page 1 of 958
- CVE-2024-50623CRITICALCVSS 9.8EG 9.8⚠ KEV2024-10-28
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
- CVE-2022-42948CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-24
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
- CVE-2019-3929CRITICALCVSS 9.8EG 9.8⚠ KEV2019-04-30
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmwar…
- CVE-2024-42009CRITICALCVSS 9.3EG 9.3⚠ KEV2024-08-05
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in prog…
- CVE-2023-34192CRITICALCVSS 9.0EG 9.0⚠ KEV2023-07-06
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
- CVE-2019-18426CRITICALCVSS 8.2EG 9.0⚠ KEV2020-01-21
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a l…
- CVE-2026-42897CRITICALCVSS 8.1EG 9.0⚠ KEV2026-05-14
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-68461CRITICALCVSS 7.2EG 9.0⚠ KEV2025-12-18
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- CVE-2020-11023CRITICALCVSS 6.9EG 9.0⚠ KEV2020-04-29
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and oth…
- CVE-2024-43573CRITICALCVSS 6.5EG 9.0⚠ KEV2024-10-08
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-44309CRITICALCVSS 6.3EG 9.0⚠ KEV2024-11-20
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted …
- CVE-2025-66376CRITICALCVSS 6.1EG 9.0⚠ KEV2026-01-05
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
- CVE-2025-48700CRITICALCVSS 6.1EG 9.0⚠ KEV2025-06-23
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potenti…
- CVE-2024-11182CRITICALCVSS 6.1EG 9.0⚠ KEV2024-11-15
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the conte…
- CVE-2024-27443CRITICALCVSS 6.1EG 9.0⚠ KEV2024-08-12
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the h…
- CVE-2024-37383CRITICALCVSS 6.1EG 9.0⚠ KEV2024-06-07
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
- CVE-2023-43770CRITICALCVSS 6.1EG 9.0⚠ KEV2023-09-22
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
- CVE-2023-37580CRITICALCVSS 6.1EG 9.0⚠ KEV2023-07-31
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
- CVE-2022-39197CRITICALCVSS 6.1EG 9.0⚠ KEV2022-09-22
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt St…
- CVE-2022-27926CRITICALCVSS 6.1EG 9.0⚠ KEV2022-04-21
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
- CVE-2022-24682CRITICALCVSS 6.1EG 9.0⚠ KEV2022-02-09
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside…
- CVE-2021-1879CRITICALCVSS 6.1EG 9.0⚠ KEV2021-04-02
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. App…
- CVE-2020-35730CRITICALCVSS 6.1EG 9.0⚠ KEV2020-12-28
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addi…
- CVE-2018-19953CRITICALCVSS 6.1EG 9.0⚠ KEV2020-10-28
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…
- CVE-2020-3580CRITICALCVSS 6.1EG 9.0⚠ KEV2020-10-21
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (X…
- CVE-2020-13965CRITICALCVSS 6.1EG 9.0⚠ KEV2020-06-09
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
- CVE-2019-9978CRITICALCVSS 6.1EG 9.0⚠ KEV2019-03-24
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
- CVE-2018-6882CRITICALCVSS 6.1EG 9.0⚠ KEV2018-03-27
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML …
- CVE-2014-2120CRITICALCVSS 6.1EG 9.0⚠ KEV2014-03-19
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
- CVE-2012-0767CRITICALCVSS 6.1EG 9.0⚠ KEV2012-02-16
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows r…
- CVE-2025-27915CRITICALCVSS 5.4EG 9.0⚠ KEV2025-03-12
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user view…
- CVE-2023-5631CRITICALCVSS 5.4EG 9.0⚠ KEV2023-10-18
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker t…
- CVE-2021-26829CRITICALCVSS 5.4EG 9.0⚠ KEV2021-06-11
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
- CVE-2018-19943CRITICALCVSS 5.4EG 9.0⚠ KEV2020-10-28
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20…
- CVE-2013-5223CRITICALCVSS 5.4EG 9.0⚠ KEV2013-11-19
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) dd…
- CVE-2026-106102CRITICALCVSS 10.0EG 10.02026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into ti…
- CVE-2026-59167CRITICALCVSS 10.0EG 10.02026-09-23
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler a…
- CVE-2026-85061CRITICALCVSS 10.0EG 10.02026-09-03
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collecti…
- CVE-2026-54433CRITICALCVSS 10.0EG 10.02026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by o…
- CVE-2025-67288CRITICALCVSS 10.0EG 10.02025-12-22
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in th…
- CVE-2025-49410CRITICALCVSS 10.0EG 10.02025-08-20
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Testimonials: from n/a through 1.1.1.
- CVE-2024-47875CRITICALCVSS 10.0EG 10.02024-10-11
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
- CVE-2024-6886CRITICALCVSS 10.0EG 10.02024-08-06
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
- CVE-2022-4361CRITICALCVSS 10.0EG 10.02023-07-07
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionCo…
- CVE-2023-28849CRITICALCVSS 10.0EG 10.02023-04-05
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be…
- CVE-2023-0018CRITICALCVSS 10.0EG 10.02023-01-10
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports conta…
- CVE-2021-36206CRITICALCVSS 10.0EG 10.02022-10-28
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
- CVE-2022-35698CRITICALCVSS 10.0EG 10.02022-10-14
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbi…
- CVE-2021-23856CRITICALCVSS 10.0EG 10.02021-10-04
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
- CVE-2021-39199CRITICALCVSS 10.0EG 10.02021-09-07
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into.…
Map vulnerabilities like CWE-79 to your infrastructure
EchelonGraph correlates every CVE — across CWE-79 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →