Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 4/793
8.9
CVE-2026-43984

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e

8.9
CVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server si

8.9
CVE-2026-57858

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa

8.9
CVE-2026-18099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to imprope

8.9
CVE-2026-30864

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip

8.9
CVE-2026-82653

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package nam

8.9
CVE-2026-82654

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rende

8.8
CVE-2025-55204

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec

8.8
CVE-2026-22256

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder

8.8
CVE-2026-22257

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder

8.8
CVE-2026-24778

Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an

8.8
CVE-2026-1819

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Elect

8.8
CVE-2025-52436

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi

8.8
CVE-2025-52468

Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi

8.8
CVE-2025-55289

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V

8.8
CVE-2025-70038

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw

8.8
CVE-2026-41421

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa

8.8
CVE-2026-3953

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In

8.8
CVE-2026-5784

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa

8.8
CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an

8.8
CVE-2026-43892

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli

8.8
CVE-2026-23819

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u

8.8
CVE-2026-3220

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress

8.8
CVE-2026-7498

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio

8.8
CVE-2026-8071

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus

8.8
CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut

8.8
CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4

8.8
CVE-2026-50178

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side

8.8
CVE-2026-7569

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem

8.8
CVE-2026-9780

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem

8.8
CVE-2026-48307

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An

8.8
CVE-2026-61875

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav

8.8
CVE-2026-61876

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ

8.8
CVE-2026-10081

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

8.8
CVE-2026-11767

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef

8.8
CVE-2026-60633

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60634

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60635

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60636

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60637

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60638

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60639

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-60664

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.8
CVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent

8.8
CVE-2026-13609

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af

8.8
CVE-2024-39024

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

8.8
CVE-2026-14293

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option

8.8
CVE-2026-57104

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an

8.8
CVE-2026-65767

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allo

8.8
CVE-2026-71386

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started