CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execut
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious admin
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (X
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke
The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which coul
The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privil
The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high
A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts o
The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plu
The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow h
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio
The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow h
The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow
The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high
The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow hi
The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and esca
In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Si
Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these
Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users
The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all
The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow hig
The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg
The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could
The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high pr
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-
An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar to
An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-le
An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sideba
An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar t
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21
The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which coul
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some o
The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could all
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c
The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could all
The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which c
The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which coul
The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its setti
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displaye
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign setti
The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow hig
The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privi
A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker
The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high pr
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started