CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings
Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management Syste
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or
The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of i
The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and esca
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which cou
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, l
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which c
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to maliciou
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts
Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high pri
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing hi
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 al
A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vu
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high priv
The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h
File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via
The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege user
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table se
The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as ad
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high pri
The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile
The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing
The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg
The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege u
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing hi
Blogifier v3.0 was discovered to contain an arbitrary file upload vulnerability at /api/storage/upload/PostImage. This v
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privile
The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the comp
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the addr
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plu
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating
The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow
The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-pri
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started