Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 265/793
2.7
CVE-2024-10102

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some

2.7
CVE-2024-10562

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could

2.7
CVE-2025-22855

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortin

2.7
CVE-2025-64745

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS)

2.6
CVE-2025-22402

Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML

2.6
CVE-2024-45712

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be

2.4
CVE-2025-0219

A vulnerability, which was classified as problematic, has been found in Trimble SPS851 488.01. Affected by this issue is

2.4
CVE-2024-13137

A vulnerability was found in wangl1989 mysiteforme 1.0. It has been classified as problematic. This affects the function

2.4
CVE-2025-0220

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part o

2.4
CVE-2025-0228

A vulnerability has been found in code-projects Local Storage Todo App 1.0 and classified as problematic. This vulnerabi

2.4
CVE-2024-13142

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been declared as problematic. This vulnerability affects

2.4
CVE-2024-13143

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the functi

2.4
CVE-2024-13202

A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the functi

2.4
CVE-2024-13205

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue

2.4
CVE-2024-13209

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function o

2.4
CVE-2025-0398

A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is

2.4
CVE-2025-0400

A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unkno

2.4
CVE-2025-0464

A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by t

2.4
CVE-2025-0537

A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0.

2.4
CVE-2025-0559

A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This i

2.4
CVE-2025-0560

A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is

2.4
CVE-2025-0706

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problem

2.4
CVE-2025-0709

A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown pr

2.4
CVE-2025-0800

A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown

2.4
CVE-2025-1174

A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vuln

2.4
CVE-2025-1332

A vulnerability has been found in FastCMS up to 0.1.5 and classified as problematic. This vulnerability affects unknown

2.4
CVE-2025-1579

A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some

2.4
CVE-2025-1585

A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the f

2.4
CVE-2025-1591

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affecte

2.4
CVE-2025-1592

A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affec

2.4
CVE-2025-1613

A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects

2.4
CVE-2025-1614

A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown

2.4
CVE-2025-1615

A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerabil

2.4
CVE-2025-1617

A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part

2.4
CVE-2025-1817

A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown cod

2.4
CVE-2025-1830

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown p

2.4
CVE-2025-1892

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of t

2.4
CVE-2024-13902

A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown

2.4
CVE-2025-2131

A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. It has been rated as problematic. This issue affects some unk

2.4
CVE-2025-2133

A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functiona

2.4
CVE-2025-2191

A vulnerability, which was classified as problematic, has been found in Claro A7600-A1 RNR4-A72T-2x16_v2110403_CLA_32_16

2.4
CVE-2025-2206

A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown pa

2.4
CVE-2025-2207

A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unkn

2.4
CVE-2025-2208

A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue aff

2.4
CVE-2025-2209

A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unkn

2.4
CVE-2025-2210

A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulne

2.4
CVE-2025-2211

A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is s

2.4
CVE-2025-2212

A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an

2.4
CVE-2025-2213

A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability

2.4
CVE-2025-2340

A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started