Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 400/793
4.8
CVE-2024-6393

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Image

4.8
CVE-2024-53278

Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us

4.8
CVE-2024-10471

The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-53620

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut

4.8
CVE-2024-53635

A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV

4.8
CVE-2024-46055

OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.

4.8
CVE-2024-10510

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of

4.8
CVE-2024-10704

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-53617

A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl

4.8
CVE-2024-10893

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al

4.8
CVE-2024-51773

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe

4.8
CVE-2024-10551

The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al

4.8
CVE-2024-48703

PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.

4.8
CVE-2024-11183

The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2023-43962

Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary co

4.8
CVE-2024-10010

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-10517

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl

4.8
CVE-2024-10518

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl

4.8
CVE-2024-9428

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2024-9641

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-9881

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-10939

The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co

4.8
CVE-2024-55100

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0

4.8
CVE-2024-37776

A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri

4.8
CVE-2024-55451

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U

4.8
CVE-2024-55864

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious

4.8
CVE-2023-37940

Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87

4.8
CVE-2023-23357

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi

4.8
CVE-2024-10555

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings,

4.8
CVE-2024-10706

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-11605

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, whic

4.8
CVE-2024-11645

The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high p

4.8
CVE-2024-11921

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the pag

4.8
CVE-2024-54451

A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.

4.8
CVE-2024-54774

Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.

4.8
CVE-2024-54775

Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /adm

4.7
CVE-2023-6737

The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p

4.7
CVE-2024-23633

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w

4.7
CVE-2024-22128

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702

4.7
CVE-2024-26481

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

4.7
CVE-2024-26281

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur

4.7
CVE-2024-22547

WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).

4.7
CVE-2024-26152

### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitize

4.7
CVE-2024-22776

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excludi

4.7
CVE-2023-52048

RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

4.7
CVE-2024-28150

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as p

4.7
CVE-2023-49986

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow att

4.7
CVE-2024-1720

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is

4.7
CVE-2022-46091

Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows att

4.7
CVE-2024-1985

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started