CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which cou
The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which co
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 a
The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes b
The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before out
The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them
The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and esca
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t
Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute
MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to inse
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi
The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with
The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes befor
ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a rend
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of
The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and a
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnera
A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest versi
The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back i
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cro
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid s
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` paramet
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea
The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high pr
The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could all
A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file wi
A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affectin
RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerabilit
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled input
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally,
Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exp
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started