Cross-Site Scripting (CWE-79)
CWE-79 covers products that place user-controllable input into a web page served to other users without neutralizing it. MITRE groups reflected, stored and DOM-based XSS under this one entry because all share the same root weakness. The early acronym CSS fell out of use to avoid confusion with Cascading Style Sheets.
About CWE-79
The most common result is disclosure of data such as session cookies, which a script can send elsewhere. Script also runs with the victim's privileges in the site, and combined with other flaws may lead to code execution on the victim's machine.
Mitigations
- +Use a vetted framework or encoding library that produces properly encoded output.
- +Encode output for its exact context, since HTML body, attributes, URIs, JavaScript and CSS each need different encoding.
- +Use structured mechanisms that enforce separation between data and code.
- +Repeat client-side checks on the server.
- +Keep client state and sensitive data on the server side where possible to shrink the input surface.
Detection
Automated static analysis has moderate effectiveness, and black box testing with automated test generation can help. Stored XSS is harder to find because the trigger may occur long after the data was stored.
CWE-79 Vulnerabilities
13 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | Microsoft | 8.1 | 0.5% | KEV | 2026-05-14 |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | Zimbra | 7.2 | 20.2% | KEV | 2026-01-05 |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability | Roundcube | 7.2 | 26.8% | KEV | 2025-12-18 |
| CVE-2024-11182 | Stored XSS vulnerability in MDaemon Email Server | MDaemon | 5.3 | 17.6% | KEV | 2024-11-15 |
| CVE-2020-11023 | Potential XSS vulnerability in jQuery | jquery | 6.9 | 84.9% | KEV | 2020-04-29 |
| CVE-2024-43573 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 6.5 | 46.1% | KEV | 2024-10-08 |
| CVE-2023-5631 | Stored XSS vulnerability in Roundcube | Roundcube | 6.1 | 75.9% | KEV | 2023-10-18 |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability | QNAP Systems Inc. | 6.1 | 29.0% | KEV | 2020-10-28 |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability | QNAP Systems Inc. | 8.0 | 21.5% | KEV | 2020-10-28 |
| CVE-2019-18426 | WhatsApp Cross-Site Scripting Vulnerability | 8.2 | 67.9% | KEV | 2020-01-21 | |
| CVE-2019-3929 | Crestron Multiple Products Command Injection Vulnerability | Crestron | 9.8 | 99.0% | KEV | 2019-04-30 |
| CVE-2020-3580 | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities | Cisco | 6.1 | 85.6% | KEV | 2020-10-21 |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 4.6 | 19.1% | 2026-04-14 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-79?→
CWE-79 is the MITRE entry for cross-site scripting. User input ends up in a web page without proper neutralization and runs as script in other users' browsers.
Are reflected, stored and DOM XSS separate CWEs?→
No. MITRE lists them as alternate terms under CWE-79 because they share the same underlying weakness.
How many exploited vulnerabilities are classified as CWE-79?→
This database lists 13 CVE records mapped to CWE-79 by their CVE Numbering Authority. 12 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-42897, CVE-2025-66376, CVE-2025-68461.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.