Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 28/793
7.1
CVE-2026-78263

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

7.1
CVE-2026-78264

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

7.1
CVE-2026-78282

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

7.1
CVE-2026-80426

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/s

7.1
CVE-2026-78261

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

7.1
CVE-2026-78281

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

7.1
CVE-2026-78283

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

7.1
CVE-2026-78289

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

7.1
CVE-2026-78293

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

7.1
CVE-2026-81760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi

6.9
CVE-2026-34530

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

6.9
CVE-2026-37980

A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real

6.9
CVE-2026-41238

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulne

6.9
CVE-2026-37503

Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade u

6.9
CVE-2026-46361

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu

6.9
CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es

6.9
CVE-2026-53667

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validatio

6.9
CVE-2026-53668

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow

6.9
CVE-2026-52873

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until versi

6.8
CVE-2025-13056

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In

6.8
CVE-2025-12511

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In

6.8
CVE-2025-12513

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In

6.8
CVE-2025-14803

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress

6.8
CVE-2025-27379

A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker

6.8
CVE-2026-24784

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i

6.8
CVE-2026-23794

Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a maliciou

6.8
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b

6.8
CVE-2026-28338

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for

6.8
CVE-2026-32112

ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters

6.8
CVE-2026-3457

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent

6.8
CVE-2026-40283

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul

6.8
CVE-2026-40284

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul

6.8
CVE-2026-41239

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior t

6.8
CVE-2026-45025

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln

6.8
CVE-2026-45026

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln

6.8
CVE-2026-33741

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use

6.8
CVE-2026-39311

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas

6.8
CVE-2026-11166

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar

6.8
CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex

6.8
CVE-2026-14827

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in

6.8
CVE-2026-13605

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca

6.8
CVE-2026-14318

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H

6.8
CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend

6.8
CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer

6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t

6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po

6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur

6.8
CVE-2026-15047

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside

6.8
CVE-2026-57279

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may

6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputti

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started