CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou
The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be
The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape
SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user r
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Admin
The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri
The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin
The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting
The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which co
MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute ar
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute
The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Tex
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The
NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQue
The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing
The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th
An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The g
An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Grow
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow mess
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes
The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Word
The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline"
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow
A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker t
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end
Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrator
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the f
The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could all
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admi
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery bef
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanit
The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started