CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Image
Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut
A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV
OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.
The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of
The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul
A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe
The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.
The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow h
Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary co
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow hi
The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which cou
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig
The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0
A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri
A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi
The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings,
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow
The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, whic
The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high p
The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the pag
A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.
Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.
Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /adm
The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p
Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702
Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur
WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitize
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excludi
RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as p
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow att
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is
Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows att
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started