CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A store
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A store
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A store
IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Jav
Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, l
There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, a
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.
The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could al
The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the
The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which
The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whene
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scri
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could
The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high priv
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape
The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does
The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields befor
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a
The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, whic
Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript c
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers,
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfigu
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplica
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSyste
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplat
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedul
The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, whi
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager a
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could all
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager c
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow h
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow hig
The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow hi
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious s
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute ar
The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high pri
The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could al
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within t
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started