Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 65/793
6.1
CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10

6.1
CVE-2026-51025

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary

6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v

6.1
CVE-2026-52475

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the

6.1
CVE-2026-64828

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac

6.1
CVE-2026-9066

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse

6.1
CVE-2026-65756

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr

6.1
CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RE

6.1
CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled n

6.1
CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int

6.1
CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function

6.1
CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont

6.1
CVE-2026-65697

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that

6.1
CVE-2026-15346

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '

6.1
CVE-2026-66010

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL

6.1
CVE-2026-8308

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa

6.1
CVE-2026-10082

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it

6.1
CVE-2026-12982

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it

6.1
CVE-2026-13400

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl

6.1
CVE-2026-14190

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input

6.1
CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th

6.1
CVE-2026-51565

Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker

6.1
CVE-2026-17528

Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.

6.1
CVE-2026-8167

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu

6.1
CVE-2026-65882

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w

6.1
CVE-2026-18084

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB

6.1
CVE-2026-14515

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptin

6.1
CVE-2026-18197

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow

6.1
CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

6.1
CVE-2026-66490

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

6.1
CVE-2025-65337

Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address

6.1
CVE-2026-17797

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-17818

Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbi

6.1
CVE-2026-17827

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-17845

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-17853

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compr

6.1
CVE-2026-17878

Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrar

6.1
CVE-2026-17962

Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitr

6.1
CVE-2026-11881

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration setting

6.1
CVE-2026-13330

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it ad

6.1
CVE-2026-14207

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field befor

6.1
CVE-2026-14592

The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks befor

6.1
CVE-2025-0152

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1

6.1
CVE-2025-51684

CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data

6.1
CVE-2025-65341

Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

6.1
CVE-2025-65342

code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

6.1
CVE-2026-61526

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through

6.1
CVE-2026-14845

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re

6.1
CVE-2026-14921

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_

6.1
CVE-2026-14922

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started