CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi
The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set
The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti
The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which
The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascrip
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/too
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the
The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p
The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v
The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv
The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address"
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word
IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged use
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV da
A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Scripting (XSS)
Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS)
Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allo
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
Tieba-Cloud-Sign v4.9 was discovered to contain a cross-site scripting (XSS) vulnerability via the function strip_tags.
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, whic
The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which co
The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputti
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could
The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow hi
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an at
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager
Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT l
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <=
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high pri
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started