Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 257/793
3.5
CVE-2025-1577

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by

3.5
CVE-2025-1586

A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerabilit

3.5
CVE-2025-1597

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic.

3.5
CVE-2025-1612

A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unk

3.5
CVE-2024-10545

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image

3.5
CVE-2025-1904

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by

3.5
CVE-2025-1905

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This a

3.5
CVE-2025-1955

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic

3.5
CVE-2025-1957

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u

3.5
CVE-2025-1967

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0.

3.5
CVE-2025-2047

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This a

3.5
CVE-2025-2049

A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown

3.5
CVE-2025-2084

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as p

3.5
CVE-2025-2085

A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of

3.5
CVE-2025-2086

A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown co

3.5
CVE-2025-2087

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s

3.5
CVE-2025-1363

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an

3.5
CVE-2025-2123

A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is t

3.5
CVE-2025-2124

A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown p

3.5
CVE-2025-2130

A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown

3.5
CVE-2024-13615

The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr

3.5
CVE-2025-2194

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file

3.5
CVE-2025-2195

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the

3.5
CVE-2025-2196

A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the fun

3.5
CVE-2025-2214

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown proces

3.5
CVE-2025-2335

A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknow

3.5
CVE-2025-1622

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul

3.5
CVE-2025-1623

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul

3.5
CVE-2025-1624

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul

3.5
CVE-2025-2364

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the fu

3.5
CVE-2025-2371

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as proble

3.5
CVE-2025-2375

A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management S

3.5
CVE-2025-2377

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by thi

3.5
CVE-2025-30345

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i

3.5
CVE-2025-2582

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unkn

3.5
CVE-2025-2583

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown pa

3.5
CVE-2025-2623

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability

3.5
CVE-2025-2645

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affect

3.5
CVE-2025-2650

A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. T

3.5
CVE-2025-2673

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an

3.5
CVE-2024-10558

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could

3.5
CVE-2024-13124

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul

3.5
CVE-2025-1062

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its

3.5
CVE-2025-1203

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its

3.5
CVE-2025-2699

A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue

3.5
CVE-2025-2700

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown

3.5
CVE-2025-2715

A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unkno

3.5
CVE-2024-10554

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic

3.5
CVE-2024-10560

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could

3.5
CVE-2024-12769

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started