CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by
A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerabilit
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic.
A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unk
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This a
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0.
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This a
A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as p
A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of
A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown co
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an
A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is t
A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown p
A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown
The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the
A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the fun
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown proces
A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknow
The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul
The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul
A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the fu
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as proble
A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management S
A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by thi
An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i
A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unkn
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown pa
A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affect
A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. T
A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could
The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its
A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue
A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown
A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unkno
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started