CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes,
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or esc
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or es
The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt
The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertisi
A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remo
The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to
The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro
The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_fie
The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin
The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti
The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTM
The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u
The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validatio
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high
The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n
The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, all
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and G
The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a
The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high pr
The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all
The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to
Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management colum
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte
The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started