Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 508/793
3.5
CVE-2023-1743

A vulnerability classified as problematic has been found in SourceCodester Grade Point Average GPA Calculator 1.0. This

3.5
CVE-2023-1746

A vulnerability, which was classified as problematic, was found in Dreamer CMS up to 3.5.0. Affected is an unknown funct

3.5
CVE-2023-1771

A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affect

3.5
CVE-2023-1772

A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part o

3.5
CVE-2023-1794

A vulnerability was found in SourceCodester Police Crime Record Management System 1.0. It has been declared as problemat

3.5
CVE-2023-1795

A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been rated as problematic. T

3.5
CVE-2023-1798

A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is s

3.5
CVE-2023-1799

A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of

3.5
CVE-2023-1851

A vulnerability classified as problematic has been found in SourceCodester Online Payroll System 1.0. This affects an un

3.5
CVE-2023-1852

A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affe

3.5
CVE-2023-1853

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0. This i

3.5
CVE-2023-1860

A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability af

3.5
CVE-2013-10022

A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPres

3.5
CVE-2014-125094

A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is

3.5
CVE-2023-1948

A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0.

3.5
CVE-2015-10098

A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Aff

3.5
CVE-2014-125095

A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected

3.5
CVE-2009-10004

A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the

3.5
CVE-2014-125096

A vulnerability was found in Fancy Gallery Plugin 1.5.12 on WordPress. It has been declared as problematic. Affected by

3.5
CVE-2014-125097

A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected

3.5
CVE-2018-25084

A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2

3.5
CVE-2022-43952

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiA

3.5
CVE-2023-1988

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected

3.5
CVE-2023-2044

A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects

3.5
CVE-2023-2055

A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulner

3.5
CVE-2023-2076

A vulnerability classified as problematic was found in Campcodes Online Traffic Offense Management System 1.0. This vuln

3.5
CVE-2023-2077

A vulnerability, which was classified as problematic, has been found in Campcodes Online Traffic Offense Management Syst

3.5
CVE-2023-2098

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been rated as problematic. Aff

3.5
CVE-2023-2099

A vulnerability classified as problematic has been found in SourceCodester Vehicle Service Management System 1.0. This a

3.5
CVE-2023-2100

A vulnerability classified as problematic was found in SourceCodester Vehicle Service Management System 1.0. This vulner

3.5
CVE-2015-10101

A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPre

3.5
CVE-2023-2153

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by t

3.5
CVE-2022-4942

A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by th

3.5
CVE-2023-2216

A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerabil

3.5
CVE-2023-2219

A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects s

3.5
CVE-2023-2220

A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an un

3.5
CVE-2012-10013

A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problema

3.5
CVE-2012-10014

A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affect

3.5
CVE-2023-2294

A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file

3.5
CVE-2023-2349

A vulnerability classified as problematic has been found in SourceCodester Service Provider Management System 1.0. Affec

3.5
CVE-2023-2350

A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b

3.5
CVE-2023-28819

Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in upload

3.5
CVE-2023-2421

A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function o

3.5
CVE-2013-10026

A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordP

3.5
CVE-2014-125100

A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerabili

3.5
CVE-2023-2475

A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown

3.5
CVE-2023-2476

A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown

3.5
CVE-2023-2477

A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability i

3.5
CVE-2023-2521

A vulnerability was found in NEXTU NEXT-7004N 3.0.1. It has been classified as problematic. Affected is an unknown funct

3.5
CVE-2017-20183

A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as prob

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started