CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject a
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arb
Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local n
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin
The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec
Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and
Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in
The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand
OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r
Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu
Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att
The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec
A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho
A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us
ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started