CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Cross-site scripting vulnerabilities

XSS315 advisories34 exploitedlatest 2026-08-25

Cross-site scripting executes attacker-controlled JavaScript in another user’s browser session. Stored XSS in admin interfaces is the dangerous variant tracked here: it turns a low-privilege foothold into admin session theft, and several appliance XSS bugs have been chained into full compromise in real attacks.

Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged cross-site scripting, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.

Latest cross-site scripting advisories

Other vulnerability classes

Remote code execution (2023)Privilege escalation (1548)Authentication bypass (1066)Denial of service (2105)Information disclosure (1543)Memory corruption (1308)Path traversal (235)Code injection (343)Unsafe deserialization (83)SQL injection (143)Server-side request forgery (109)
New cross-site scripting advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.