Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 406/793
4.3
CVE-2024-29881

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s cont

4.3
CVE-2024-2113

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-

4.3
CVE-2024-3084

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been rated as problematic. This is

4.3
CVE-2024-3086

A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by thi

4.3
CVE-2024-2435

For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script

4.3
CVE-2024-3377

A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vu

4.3
CVE-2024-3378

A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vu

4.3
CVE-2024-32333

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under t

4.3
CVE-2022-34561

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML vi

4.3
CVE-2024-33670

Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a u

4.3
CVE-2024-2908

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow

4.3
CVE-2024-3192

A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown

4.3
CVE-2024-3194

A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some

4.3
CVE-2024-4348

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the

4.3
CVE-2024-34061

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se

4.3
CVE-2024-2744

The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow

4.3
CVE-2024-5123

A vulnerability classified as problematic has been found in SourceCodester Event Registration System 1.0. This affects a

4.3
CVE-2024-33525

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational uni

4.3
CVE-2024-34000

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

4.3
CVE-2024-5897

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro

4.3
CVE-2024-6183

A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of th

4.3
CVE-2022-38055

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Foru

4.3
CVE-2024-6273

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by

4.3
CVE-2024-4957

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all

4.3
CVE-2024-6355

A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as proble

4.3
CVE-2024-38857

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attacker

4.3
CVE-2024-3410

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allo

4.3
CVE-2024-21154

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Human Resources)

4.3
CVE-2024-7321

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulner

4.3
CVE-2024-41953

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such

4.3
CVE-2024-6254

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc

4.3
CVE-2024-7709

A vulnerability, which was classified as problematic, has been found in OcoMon 4.0RC1/4.0/5.0RC1. This issue affects som

4.3
CVE-2024-7739

A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unkn

4.3
CVE-2024-43317

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss U

4.3
CVE-2024-7976

Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp

4.3
CVE-2024-8035

Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker

4.3
CVE-2024-8112

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown pro

4.3
CVE-2024-8174

A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vu

4.3
CVE-2024-8366

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This a

4.3
CVE-2024-45399

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indi

4.3
CVE-2023-50366

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi

4.3
CVE-2024-8521

A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index o

4.3
CVE-2024-8566

A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects u

4.3
CVE-2024-7687

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well

4.3
CVE-2024-8604

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects

4.3
CVE-2024-8605

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affect

4.3
CVE-2020-24061

Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attac

4.3
CVE-2024-8866

A vulnerability was found in AutoCMS 5.4. It has been classified as problematic. This affects an unknown part of the fil

4.3
CVE-2024-38221

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.3
CVE-2024-9300

A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulner

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started