Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 83/793
5.4
CVE-2026-72559

A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent

5.4
CVE-2026-9318

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows

5.4
CVE-2026-15249

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i

5.4
CVE-2026-16066

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it

5.4
CVE-2026-19217

The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM

5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri

5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.

5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js

5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc

5.4
CVE-2026-72821

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field op

5.4
CVE-2026-72832

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss()

5.4
CVE-2026-14230

The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJ

5.4
CVE-2026-13712

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before ou

5.4
CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informat

5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, secti

5.4
CVE-2026-75834

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/sr

5.4
CVE-2026-41921

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase sugges

5.4
CVE-2026-40508

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler

5.4
CVE-2026-76346

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

5.4
CVE-2026-73254

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML pa

5.4
CVE-2026-73259

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-enco

5.4
CVE-2026-55491

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record

5.4
CVE-2026-69229

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authent

5.4
CVE-2026-10618

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendere

5.4
CVE-2026-55805

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core

5.4
CVE-2026-45694

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera

5.4
CVE-2026-81731

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description

5.4
CVE-2026-73827

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-77838

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-78238

SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-38725

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v

5.4
CVE-2026-4378

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof

5.4
CVE-2026-55779

Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i

5.3
CVE-2026-1391

The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a

5.3
CVE-2026-25144

Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter i

5.3
CVE-2026-1769

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr

5.3
CVE-2013-20005

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative act

5.3
CVE-2026-6779

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

5.3
CVE-2025-31970

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic

5.3
CVE-2026-8391

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir

5.3
CVE-2021-47934

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts

5.3
CVE-2026-4293

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be

5.3
CVE-2026-8474

A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  *

5.2
CVE-2025-68709

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe

5.2
CVE-2026-44387

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I

5.1
CVE-2026-42150

wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb

5.0
CVE-2022-50891

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr

5.0
CVE-2026-1446

There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli

5.0
CVE-2025-27852

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started