Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 258/793
3.5
CVE-2024-13122

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi

3.5
CVE-2024-13123

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi

3.5
CVE-2025-0717

To exploit the vulnerability, it is necessary:

3.5
CVE-2025-1452

The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high pr

3.5
CVE-2024-12683

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could

3.5
CVE-2025-2974

A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability af

3.5
CVE-2025-2975

A vulnerability was found in GFI KerioConnect 10.0.6 and classified as problematic. This issue affects some unknown proc

3.5
CVE-2025-2976

A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown func

3.5
CVE-2025-2977

A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerabilit

3.5
CVE-2025-2981

A vulnerability, which was classified as problematic, has been found in Legrand SMS PowerView 1.x. This issue affects so

3.5
CVE-2025-3004

A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulne

3.5
CVE-2025-3005

A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is s

3.5
CVE-2025-3152

A vulnerability classified as problematic has been found in caipeichao ThinkOX 1.0. This affects an unknown part of the

3.5
CVE-2025-3219

A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown

3.5
CVE-2025-3251

A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part

3.5
CVE-2025-3252

A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unkn

3.5
CVE-2025-3253

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown proc

3.5
CVE-2025-3297

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a

3.5
CVE-2025-3326

A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unkn

3.5
CVE-2025-3327

A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown proc

3.5
CVE-2025-3387

A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknow

3.5
CVE-2025-3389

A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue

3.5
CVE-2025-3390

A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the

3.5
CVE-2025-3391

A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this v

3.5
CVE-2025-3392

A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue

3.5
CVE-2025-3393

A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been cla

3.5
CVE-2025-3560

A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown

3.5
CVE-2025-3568

A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerab

3.5
CVE-2025-3570

A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This af

3.5
CVE-2025-3591

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this

3.5
CVE-2025-3592

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This aff

3.5
CVE-2025-3613

A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unkn

3.5
CVE-2024-11924

The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som

3.5
CVE-2025-1523

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all

3.5
CVE-2025-1524

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all

3.5
CVE-2025-1525

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all

3.5
CVE-2025-3788

A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is a

3.5
CVE-2025-3789

A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown

3.5
CVE-2025-46618

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

3.5
CVE-2025-3958

A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a

3.5
CVE-2025-3961

A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno

3.5
CVE-2025-3962

A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects

3.5
CVE-2024-52887

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing

3.5
CVE-2025-3965

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability

3.5
CVE-2025-3970

A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of

3.5
CVE-2025-3999

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2

3.5
CVE-2025-4000

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Aff

3.5
CVE-2024-9771

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig

3.5
CVE-2025-0627

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i

3.5
CVE-2025-4011

A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affe

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started