CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which
Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker
The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputt
The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputt
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings,
The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcod
The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could
IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb
The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which
The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] pa
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability al
AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regul
An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious li
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is expl
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could le
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t
The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patc
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name
Cervantes through 0.5-alpha allows stored XSS.
The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] pa
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privile
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from t
The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could
Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow hig
The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload w
Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerab
The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before output
Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltunge
The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which
The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a r
Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all v
Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scriptin
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started