Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 63/793
6.1
CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script

6.1
CVE-2026-50555

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50556

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-56698

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio

6.1
CVE-2026-10857

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp

6.1
CVE-2026-56263

Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U

6.1
CVE-2026-34915

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a l

6.1
CVE-2026-46547

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in t

6.1
CVE-2026-8622

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia

6.1
CVE-2026-8628

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver

6.1
CVE-2026-11878

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Ma

6.1
CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu

6.1
CVE-2026-39900

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflecte

6.1
CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both

6.1
CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script w

6.1
CVE-2026-50765

A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man

6.1
CVE-2026-13245

The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' para

6.1
CVE-2026-57326

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

6.1
CVE-2026-57958

Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to e

6.1
CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr

6.1
CVE-2026-52760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A

6.1
CVE-2026-8403

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electroni

6.1
CVE-2026-13836

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-14000

Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-14001

Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbi

6.1
CVE-2026-14068

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who con

6.1
CVE-2026-14145

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-14147

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-50040

Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed

6.1
CVE-2026-13015

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place'

6.1
CVE-2026-12754

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '

6.1
CVE-2026-58030

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

6.1
CVE-2026-58032

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

6.1
CVE-2026-58037

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

6.1
CVE-2026-58038

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

6.1
CVE-2026-14358

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun

6.1
CVE-2025-71385

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi

6.1
CVE-2026-4322

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web

6.1
CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back

6.1
CVE-2026-50133

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to

6.1
CVE-2026-59711

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr

6.1
CVE-2026-59710

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta

6.1
CVE-2026-8306

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information

6.1
CVE-2026-48949

Lack of validation leads to an XSS vulnerability in the MFA management views.

6.1
CVE-2026-48950

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

6.1
CVE-2026-48951

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

6.1
CVE-2026-48952

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

6.1
CVE-2026-48953

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

6.1
CVE-2026-48954

Improper validation leads to a generic XSS vector in the language override feature.

6.1
CVE-2026-11798

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started