Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 259/793
3.5
CVE-2024-12273

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could

3.5
CVE-2025-46350

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at

3.5
CVE-2025-3513

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h

3.5
CVE-2025-3514

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h

3.5
CVE-2025-4256

A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file

3.5
CVE-2025-4257

A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown pro

3.5
CVE-2025-23379

Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During We

3.5
CVE-2023-7303

A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This

3.5
CVE-2025-4495

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability i

3.5
CVE-2025-4551

A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown fu

3.5
CVE-2024-11140

The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of i

3.5
CVE-2024-3996

The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow

3.5
CVE-2024-4002

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set

3.5
CVE-2024-4004

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could

3.5
CVE-2024-4091

The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul

3.5
CVE-2024-6711

The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which

3.5
CVE-2025-4744

A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affect

3.5
CVE-2025-4745

A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affect

3.5
CVE-2025-5007

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability i

3.5
CVE-2025-5127

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the fil

3.5
CVE-2025-5134

A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an u

3.5
CVE-2025-5138

A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability

3.5
CVE-2025-5153

A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some

3.5
CVE-2025-5181

A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor

3.5
CVE-2025-5405

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b5

3.5
CVE-2025-5411

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects th

3.5
CVE-2025-5412

A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function

3.5
CVE-2025-5420

A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unk

3.5
CVE-2025-5513

A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vuln

3.5
CVE-2025-5523

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.u

3.5
CVE-2025-5628

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected b

3.5
CVE-2025-5651

A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1

3.5
CVE-2025-5713

A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250519 and classified as problematic. Affected by this is

3.5
CVE-2025-5757

A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec

3.5
CVE-2025-5764

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s

3.5
CVE-2025-5765

A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un

3.5
CVE-2025-5796

A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability aff

3.5
CVE-2025-5797

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unk

3.5
CVE-2025-5879

A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unkno

3.5
CVE-2025-5884

A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an

3.5
CVE-2025-5886

A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing

3.5
CVE-2025-5887

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun

3.5
CVE-2025-5974

A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0.

3.5
CVE-2025-5976

A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnera

3.5
CVE-2025-5984

A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe

3.5
CVE-2025-6127

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Aff

3.5
CVE-2025-6287

A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by thi

3.5
CVE-2025-6340

A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects a

3.5
CVE-2025-6345

A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is

3.5
CVE-2025-6353

A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started