Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 66/793
6.1
CVE-2026-52232

A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build

6.1
CVE-2026-17571

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

6.1
CVE-2026-18344

The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par

6.1
CVE-2026-14841

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle

6.1
CVE-2026-13340

The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz ext

6.1
CVE-2026-15383

The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whic

6.1
CVE-2026-15931

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthent

6.1
CVE-2026-69149

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-69151

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-38444

osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is

6.1
CVE-2026-38446

A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e

6.1
CVE-2026-66296

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit

6.1
CVE-2026-51144

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker

6.1
CVE-2026-52370

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu

6.1
CVE-2026-8790

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete

6.1
CVE-2026-16583

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8

6.1
CVE-2026-17505

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v

6.1
CVE-2026-17532

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p

6.1
CVE-2026-71249

299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f

6.1
CVE-2026-53992

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot

6.1
CVE-2025-15678

The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use

6.1
CVE-2026-11588

The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route

6.1
CVE-2026-71435

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag

6.1
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes

6.1
CVE-2026-14331

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a

6.1
CVE-2026-15032

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an

6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r

6.1
CVE-2026-16032

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an

6.1
CVE-2026-17019

The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and

6.1
CVE-2026-69116

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.

6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio

6.1
CVE-2026-72925

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi

6.1
CVE-2026-73084

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi

6.1
CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions

6.1
CVE-2026-17013

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it

6.1
CVE-2026-48550

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via

6.1
CVE-2026-19657

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker wh

6.1
CVE-2026-73628

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-UR

6.1
CVE-2026-73572

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla

6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter

6.1
CVE-2026-73038

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to esca

6.1
CVE-2026-73531

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers

6.1
CVE-2026-56858

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitr

6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vu

6.1
CVE-2026-19712

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in

6.1
CVE-2026-50771

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary co

6.1
CVE-2026-63670

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed e

6.1
CVE-2026-67925

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpo

6.1
CVE-2026-30250

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90

6.1
CVE-2026-52606

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitr

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started