CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it ba
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter befor
The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in th
Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Ma
Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cro
The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in
Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displayin
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_ta
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\ad
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it b
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allo
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a si
ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injec
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unaut
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware con
A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to ex
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F
The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive Sch
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive Schoo
A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the contex
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx w
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Managem
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all ve
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, act
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML c
Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t
The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in v
The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ pa
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unaut
The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Managemen
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earl
The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lh_add_media_fro
The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in C
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execut
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started