Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 245/793
4.8
CVE-2024-13384

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some

4.8
CVE-2024-13482

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-13486

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-13616

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting

4.8
CVE-2024-13621

The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-13729

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co

4.8
CVE-2024-13730

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-1663

The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w

4.8
CVE-2024-2643

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin

4.8
CVE-2024-2869

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-3062

The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh

4.8
CVE-2024-5026

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all

4.8
CVE-2024-6335

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a

4.8
CVE-2024-6462

The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-6478

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic

4.8
CVE-2024-6665

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh

4.8
CVE-2024-6693

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv

4.8
CVE-2024-6708

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting

4.8
CVE-2024-6713

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-6797

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-6798

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2024-7556

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-7758

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all

4.8
CVE-2024-7759

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-7769

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-8187

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8284

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8426

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-8492

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri

4.8
CVE-2024-8493

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-8542

The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8617

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high

4.8
CVE-2024-8618

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-8619

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo

4.8
CVE-2024-8620

The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8670

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-8701

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8702

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2024-8759

The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-9182

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv

4.8
CVE-2024-9227

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set

4.8
CVE-2024-9236

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil

4.8
CVE-2024-9390

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al

4.8
CVE-2024-9882

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does

4.8
CVE-2025-0329

The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou

4.8
CVE-2025-1033

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2025-1289

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2025-47786

Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that all

4.8
CVE-2025-2524

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2025-2560

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started