CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels b
The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged
The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high
The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which
The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su
The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing
The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privileg
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou
The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege use
The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile
The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow
The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a
The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig
The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.p
FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Pan
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, whi
The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high
The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Wor
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users suc
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By explo
The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig
The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execu
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them bac
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCo
Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.
Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_catego
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the Maia
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its sett
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started