We have discovered 16,071,221 live websites that are affected by CWE-79.
![]() | 5,808,701 websites |
![]() | 1,597,750 websites |
![]() | 823,944 websites |
![]() | 789,305 websites |
![]() | 649,287 websites |
![]() | 499,417 websites |
![]() | 487,355 websites |
![]() | 434,152 websites |
![]() | 334,419 websites |
![]() | 304,060 websites |
.com | 7,006,865 websites |
.de | 891,029 websites |
.org | 681,096 websites |
.ru | 568,395 websites |
.net | 480,842 websites |
.co.uk | 406,604 websites |
.nl | 401,890 websites |
.it | 390,325 websites |
.fr | 304,549 websites |
.com.br | 266,336 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
Jul, 2025 | CVE-2024-9343 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in th... | 2 |
Jul, 2025 | CVE-2024-10029 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in... | 2 |
Jul, 2025 | CVE-2024-10032 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in th... | 2 |
Jul, 2025 | CVE-2025-2799 | WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting | 7,309 |
Jul, 2025 | CVE-2025-2800 | WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name' | 8,091 |
Jul, 2025 | CVE-2025-5284 | Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | 5,077 |
Jul, 2025 | CVE-2025-5845 | Affiliate Reviews <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via numColumns Parameter | 42 |
Jul, 2025 | CVE-2025-6747 | Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | 82,152 |
Jul, 2025 | CVE-2025-6977 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function | 1,108 |
Jul, 2025 | CVE-2025-7035 | Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes | 73 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Apr, 2020 | CVE-2020-11023 | Potential XSS vulnerability in jQuery | 8,178,603 |
Apr, 2020 | CVE-2020-11022 | Potential XSS vulnerability in jQuery | 8,170,708 |
Jan, 2022 | CVE-2022-21662 | Stored XSS in WordPress | 1,693,783 |
Jul, 2022 | CVE-2022-31160 | jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label | 1,563,913 |
Jun, 2025 | CVE-2025-4965 | WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder | 1,465,463 |
Oct, 2021 | CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | 1,434,846 |
Oct, 2021 | CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | 1,434,846 |
Oct, 2021 | CVE-2021-41184 | XSS in the `of` option of the `.position()` util | 1,434,846 |
Oct, 2024 | CVE-2024-8107 | Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | 1,310,749 |
Jul, 2024 | CVE-2024-37449 | WordPress Slider Revolution plugin <= 6.7.13 - Cross Site Scripting (XSS) vulnerability | 1,231,867 |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.org | ![]() | * | |
**********.***********.com | ![]() | ** | |
********.****.br | ![]() | ** | |
*********.com | ![]() | ** | |
*******.com | ![]() | *** | |
*********.com | ![]() | *** | |
***********.com | ![]() | *** | |
******.com | ![]() | *** | |
***************.org | ![]() | *** | |
******.net | ![]() | *** |