Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 191/793
6.1
CVE-2024-13226

The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it ba

6.1
CVE-2025-0930

Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScr

6.1
CVE-2025-22994

O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.

6.1
CVE-2024-42671

A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirec

6.1
CVE-2024-49349

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored

6.1
CVE-2024-53943

An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln

6.1
CVE-2024-50656

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi

6.1
CVE-2024-44449

Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat

6.1
CVE-2024-13114

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter

6.1
CVE-2024-13325

The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page

6.1
CVE-2024-13326

The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p

6.1
CVE-2024-13327

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa

6.1
CVE-2024-13328

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in

6.1
CVE-2024-13331

The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back

6.1
CVE-2024-13332

The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the

6.1
CVE-2025-0368

The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting i

6.1
CVE-2024-40700

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vul

6.1
CVE-2025-20179

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote

6.1
CVE-2024-57427

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improper

6.1
CVE-2024-52892

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows

6.1
CVE-2024-13492

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back

6.1
CVE-2024-52882

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization

6.1
CVE-2025-25247

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webco

6.1
CVE-2025-1175

Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions betw

6.1
CVE-2024-13010

The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,

6.1
CVE-2025-24867

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (

6.1
CVE-2025-1145

NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote att

6.1
CVE-2024-13543

The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it ba

6.1
CVE-2024-13570

The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it bac

6.1
CVE-2024-13830

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a

6.1
CVE-2024-12833

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows n

6.1
CVE-2024-13749

The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2

6.1
CVE-2023-49780

Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on

6.1
CVE-2024-51122

Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote att

6.1
CVE-2024-57601

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbit

6.1
CVE-2024-12586

The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting

6.1
CVE-2024-13867

The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the

6.1
CVE-2025-1271

Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malici

6.1
CVE-2025-25990

Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the

6.1
CVE-2025-25296

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` en

6.1
CVE-2024-13603

The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut

6.1
CVE-2024-11376

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin

6.1
CVE-2025-0864

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Refle

6.1
CVE-2025-0981

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a

6.1
CVE-2024-13508

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all

6.1
CVE-2025-25054

Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Facto

6.1
CVE-2024-12069

The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou

6.1
CVE-2024-12339

The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet

6.1
CVE-2024-13711

The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers

6.1
CVE-2024-13736

The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started