CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou
The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co
The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou
The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin
The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could
The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh
The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all
The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a
The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow
The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic
The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh
The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h
The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high
The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi
The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig
The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all
The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high
The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig
The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow
The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul
The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h
The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow
The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high
The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul
The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo
The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow
The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul
The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow
The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi
The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high
The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set
The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does
The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow
Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that all
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started