CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr
The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr
The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow h
The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which coul
The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could all
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting
The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-p
An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Na
The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allow
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain a
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Prof
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc
Improper Neutralization of Input During Web Page Generation in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP For The Win bbPress Voting plugin <= 2.1.11.0 versi
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on e
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundr
The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter
This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page de
This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter wi
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes ce
Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site script
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM pro
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sop
A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function uplo
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return
IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerab
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to
IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability all
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started