CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings,
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system
The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat
The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all
The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could
A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Gene
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi
The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a paramete
The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow
The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, whi
The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett
The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some
The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig
The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape
The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo
The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow
The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could
The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, whi
The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high pr
The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its
The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which cou
The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high p
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high
The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which
The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo
The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr
The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr
The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before
The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h
The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr
The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv
The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could
The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started