CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown pro
Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During We
A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability i
A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown fu
The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of i
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set
The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could
The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which
A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affect
A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affect
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability i
A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the fil
A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an u
A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability
A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some
A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor
A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b5
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects th
A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function
A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unk
A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vuln
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.u
A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected b
A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250519 and classified as problematic. Affected by this is
A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s
A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un
A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability aff
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unk
A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unkno
A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an
A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun
A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0.
A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnera
A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Aff
A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by thi
A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects a
A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is
A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started