Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 25/793
7.1
CVE-2026-57741

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newslet

7.1
CVE-2026-57745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18

7.1
CVE-2026-57814

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your Al

7.1
CVE-2026-57816

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel B

7.1
CVE-2026-59516

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative S

7.1
CVE-2026-57101

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una

7.1
CVE-2026-12978

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the

7.1
CVE-2026-12970

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri

7.1
CVE-2026-9833

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape

7.1
CVE-2026-57370

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

7.1
CVE-2026-57374

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

7.1
CVE-2026-57397

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

7.1
CVE-2026-57427

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

7.1
CVE-2026-57428

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

7.1
CVE-2026-57699

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

7.1
CVE-2026-57701

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

7.1
CVE-2026-57704

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

7.1
CVE-2026-57735

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

7.1
CVE-2026-57767

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

7.1
CVE-2026-57769

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

7.1
CVE-2026-57809

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

7.1
CVE-2026-59512

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

7.1
CVE-2026-59517

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

7.1
CVE-2026-61944

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

7.1
CVE-2026-61947

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

7.1
CVE-2026-65492

Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.

7.1
CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

7.1
CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.

7.1
CVE-2026-15968

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr

7.1
CVE-2026-13726

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons

7.1
CVE-2026-59553

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

7.1
CVE-2026-59556

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

7.1
CVE-2026-59558

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

7.1
CVE-2026-61957

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

7.1
CVE-2026-65437

Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

7.1
CVE-2026-65438

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

7.1
CVE-2026-65439

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

7.1
CVE-2026-65440

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

7.1
CVE-2026-65441

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

7.1
CVE-2026-65443

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

7.1
CVE-2026-65446

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

7.1
CVE-2026-65447

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

7.1
CVE-2026-14870

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e

7.1
CVE-2026-14234

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin

7.1
CVE-2026-14239

The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro

7.1
CVE-2026-13725

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user

7.1
CVE-2026-28082

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

7.1
CVE-2026-28141

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

7.1
CVE-2026-28143

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

7.1
CVE-2026-28177

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started