Symantec has
released on April 8th the most recent and very interesting
Internet Security Threat Report (ISTR Volume XIII) [PDF]. Concerning the metric for site-specific XSS vulnerabilities, data is provided by us and is limited to the XSS issues that security researchers
submit to the
archive. Therefore, it provides insight into site-specific vulnerabilities rather than a complete picture of all publicly known XSS issues.
I highly recommend that you fully read it!
Quoted from the report's introduction:Table 1. Site-specific Vulnerabilities
Source: Symantec Corporation