CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 113
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to injec
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows r
Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/con
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in
The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high priv
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF
Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organi
A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when ed
Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component.
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting i
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privile
A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the ad
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permission
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which cou
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descr
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow h
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high priv
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of eve
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an
The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, whic
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicio
The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users su
The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high priv
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started