Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 196/793
6.1
CVE-2025-29688

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr

6.1
CVE-2025-29689

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr

6.1
CVE-2025-29690

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr

6.1
CVE-2025-29691

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr

6.1
CVE-2025-47783

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an at

6.1
CVE-2025-44180

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={bra

6.1
CVE-2025-44181

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via

6.1
CVE-2025-44182

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modeln

6.1
CVE-2025-44183

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via t

6.1
CVE-2023-6541

The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as

6.1
CVE-2023-7228

The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauth

6.1
CVE-2023-7230

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users

6.1
CVE-2024-11141

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing C

6.1
CVE-2024-12724

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in th

6.1
CVE-2024-12725

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting

6.1
CVE-2024-12726

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page,

6.1
CVE-2024-12732

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac

6.1
CVE-2024-12733

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac

6.1
CVE-2024-12734

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sani

6.1
CVE-2024-12873

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back

6.1
CVE-2024-13619

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p

6.1
CVE-2024-13727

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th

6.1
CVE-2024-13823

The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba

6.1
CVE-2024-13828

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the

6.1
CVE-2024-13865

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the p

6.1
CVE-2024-6667

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu

6.1
CVE-2024-6712

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as

6.1
CVE-2024-7761

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you

6.1
CVE-2024-8095

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well

6.1
CVE-2024-8703

The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the

6.1
CVE-2025-0687

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape

6.1
CVE-2025-0688

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape

6.1
CVE-2025-1286

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting

6.1
CVE-2025-1303

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in

6.1
CVE-2025-40632

Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to mod

6.1
CVE-2025-47931

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Sit

6.1
CVE-2025-47946

Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.

6.1
CVE-2025-48206

The ns_backup extension through 13.0.0 for TYPO3 allows XSS.

6.1
CVE-2025-20246

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a

6.1
CVE-2025-20247

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a

6.1
CVE-2025-20250

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a

6.1
CVE-2024-57529

Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c

6.1
CVE-2025-45755

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the S

6.1
CVE-2025-5062

The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p

6.1
CVE-2024-5962

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due

6.1
CVE-2024-48704

Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter

6.1
CVE-2024-51099

A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi

6.1
CVE-2025-44998

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows

6.1
CVE-2025-3869

The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9.

6.1
CVE-2025-1985

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started