Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 82/793
5.4
CVE-2026-48536

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio

5.4
CVE-2026-48537

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati

5.4
CVE-2026-48538

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat

5.4
CVE-2026-48539

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf

5.4
CVE-2026-57530

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk

5.4
CVE-2026-57531

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo

5.4
CVE-2026-66029

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent

5.4
CVE-2026-66030

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen

5.4
CVE-2026-66031

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent

5.4
CVE-2026-17728

Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject a

5.4
CVE-2026-17734

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arb

5.4
CVE-2026-17903

Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local n

5.4
CVE-2025-36298

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0

5.4
CVE-2025-36431

IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera

5.4
CVE-2026-11383

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri

5.4
CVE-2026-34495

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

5.4
CVE-2026-62324

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem

5.4
CVE-2026-12696

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in

5.4
CVE-2026-14292

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t

5.4
CVE-2026-15234

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin

5.4
CVE-2026-15262

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out

5.4
CVE-2026-14864

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s

5.4
CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m

5.4
CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont

5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th

5.4
CVE-2026-49131

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir

5.4
CVE-2026-49132

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec

5.4
CVE-2026-52520

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/

5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and

5.4
CVE-2026-67196

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in

5.4
CVE-2026-16942

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand

5.4
CVE-2026-71275

OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r

5.4
CVE-2026-70440

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a

5.4
CVE-2026-70441

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag

5.4
CVE-2026-16537

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin

5.4
CVE-2026-18395

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o

5.4
CVE-2026-8166

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu

5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable

5.4
CVE-2026-15245

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con

5.4
CVE-2026-15386

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att

5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it

5.4
CVE-2026-17010

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o

5.4
CVE-2026-72570

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec

5.4
CVE-2026-72576

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho

5.4
CVE-2026-72583

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us

5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome

5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo

5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out

5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb

5.4
CVE-2026-72553

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started