Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 570/793
4.8
CVE-2022-2574

The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could

4.8
CVE-2022-3139

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high p

4.8
CVE-2022-26375

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on Wor

4.8
CVE-2022-40311

Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.

4.8
CVE-2022-36368

Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a

4.8
CVE-2022-3350

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could all

4.8
CVE-2022-3391

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2022-3392

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2021-36858

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.

4.8
CVE-2022-3237

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege u

4.8
CVE-2022-3408

The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2022-3420

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, w

4.8
CVE-2022-3441

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2022-43076

A cross-site scripting (XSS) vulnerability in /admin/edit-admin.php of Web-Based Student Clearance System v1.0 allows at

4.8
CVE-2022-43078

A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Web-Based Student Clearance System v1.0 allows attac

4.8
CVE-2022-43084

A cross-site scripting (XSS) vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to e

4.8
CVE-2022-43361

Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the co

4.8
CVE-2022-44576

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in AgentEasy Properties plugin <= 1.0.4 on WordPress.

4.8
CVE-2022-44586

Auth. (admin+) Stored Cross-Site Scripting (XSS) in Ayoub Media AM-HiLi plugin <= 1.0 on WordPress.

4.8
CVE-2022-43372

Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.

4.8
CVE-2022-36428

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.

4.8
CVE-2022-20969

A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker t

4.8
CVE-2022-27894

The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an att

4.8
CVE-2022-3462

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2022-43046

Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the compone

4.8
CVE-2022-41432

EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the

4.8
CVE-2022-41433

EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the

4.8
CVE-2022-30545

Auth. Reflected Cross-Site Scripting (XSS) vulnerability in 5 Anker Connect plugin <= 1.2.6 on WordPress.

4.8
CVE-2022-32776

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense

4.8
CVE-2022-41980

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mantenimiento web plugin <= 0.13 on WordPress.

4.8
CVE-2022-3469

The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow h

4.8
CVE-2022-3539

The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and es

4.8
CVE-2022-3631

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, wh

4.8
CVE-2022-43688

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting

4.8
CVE-2022-43695

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting

4.8
CVE-2022-40846

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing

4.8
CVE-2022-20831

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20832

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20833

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20834

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20835

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20836

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20838

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20839

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20840

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20843

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20872

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20905

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20932

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

4.8
CVE-2022-20935

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started