Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 244/793
4.8
CVE-2024-13610

The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings,

4.8
CVE-2025-29280

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system

4.8
CVE-2024-10680

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-40074

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat

4.8
CVE-2025-2162

The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all

4.8
CVE-2025-1453

The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could

4.8
CVE-2025-29568

A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects

4.8
CVE-2025-45007

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Gene

4.8
CVE-2024-13381

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could

4.8
CVE-2025-3502

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high

4.8
CVE-2025-3503

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high

4.8
CVE-2025-3504

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high

4.8
CVE-2025-3583

The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2025-44184

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi

4.8
CVE-2023-5529

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which

4.8
CVE-2023-5932

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a paramete

4.8
CVE-2023-6783

The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2023-7168

The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, whi

4.8
CVE-2024-10054

The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-10107

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett

4.8
CVE-2024-10143

The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett

4.8
CVE-2024-10144

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some

4.8
CVE-2024-10145

The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-10149

The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo

4.8
CVE-2024-10362

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of

4.8
CVE-2024-10475

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape

4.8
CVE-2024-10632

The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo

4.8
CVE-2024-10639

The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-11109

The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-11189

The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, whi

4.8
CVE-2024-11190

The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-11221

The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its

4.8
CVE-2024-11266

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-11843

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high p

4.8
CVE-2024-12679

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-12680

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-12716

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which

4.8
CVE-2024-12739

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo

4.8
CVE-2024-12743

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-12770

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-12800

The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile

4.8
CVE-2024-12808

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before

4.8
CVE-2024-12874

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-13053

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-13127

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-13128

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-13313

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-13357

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv

4.8
CVE-2024-13382

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-13383

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started