We have discovered 15,196,816 live websites that are affected by CWE-79.
| 4,808,043 websites | |
| 1,398,684 websites | |
| 728,427 websites | |
| 651,284 websites | |
| 624,037 websites | |
| 591,335 websites | |
| 506,311 websites | |
| 473,485 websites | |
| 336,419 websites | |
| 325,760 websites |
| .com | 6,561,997 websites |
| .de | 878,303 websites |
| .org | 656,214 websites |
| .ru | 537,107 websites |
| .net | 440,722 websites |
| .nl | 414,003 websites |
| .co.uk | 395,635 websites |
| .it | 367,681 websites |
| .fr | 307,548 websites |
| .pl | 249,957 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2026 | CVE-2026-3498 | BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clientId' Block Attribute | 364 |
| Apr, 2026 | CVE-2026-4895 | Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute | 1,285 |
| Apr, 2026 | CVE-2026-3005 | List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode | 1 |
| Apr, 2026 | CVE-2026-4336 | Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content | 709 |
| Apr, 2026 | CVE-2026-4429 | OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute | 8,155 |
| Apr, 2026 | CVE-2026-5357 | Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | 33,595 |
| Apr, 2026 | CVE-2026-5742 | UsersWP <= 1.2.60 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Substitution | 3,469 |
| Apr, 2026 | CVE-2025-1794 | AM LottiePlayer <= 3.6.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG | 36 |
| Apr, 2026 | CVE-2026-1396 | Magic Conversation For Gravity Forms <= 3.0.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | 5 |
| Apr, 2026 | CVE-2026-2481 | Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' | 68,244 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2020 | CVE-2020-11023 | Potential XSS vulnerability in jQuery | 7,099,257 |
| Mar, 2026 | CVE-2026-3427 | Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute | 3,738,996 |
| Apr, 2020 | CVE-2020-11022 | jQuery has a potential XSS vulnerability | 3,491,397 |
| Feb, 2026 | CVE-2026-1293 | Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute | 2,502,255 |
| Jan, 2022 | CVE-2022-21662 | Stored XSS in WordPress | 1,383,904 |
| Dec, 2025 | CVE-2025-11220 | Elementor <= 3.33.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path | 1,309,537 |
| Mar, 2024 | CVE-2024-2242 | Contact Form 7 <= 5.9 - Reflected Cross-Site Scripting | 1,286,532 |
| Jul, 2022 | CVE-2022-31160 | jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label | 1,284,913 |
| Oct, 2021 | CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | 1,184,778 |
| Oct, 2021 | CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | 1,184,778 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | * | ||
| **********.***********.com | ** | ||
| ********.****.br | ** | ||
| *********.com | ** | ||
| *********.com | *** | ||
| *******.com | *** | ||
| *********.com | *** | ||
| ***********.com | *** | ||
| ******.com | *** | ||
| ***************.org | *** |