CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting syste
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Setting
Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at Wor
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object p
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at W
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plu
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 a
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to oth
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allow
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its setting
The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high
The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high
The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could all
The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high pr
Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQ
The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could a
The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high priv
The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege u
The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege user
The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise t
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress.
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.
The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users suc
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users su
The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users t
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73
The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could a
The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow
The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could al
The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high pr
The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high p
The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in fr
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow hig
The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow
The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privile
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Boos
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege us
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started