Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 87/793
4.8
CVE-2025-15669

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren

4.8
CVE-2025-15675

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

4.8
CVE-2026-67612

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al

4.8
CVE-2026-67617

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al

4.8
CVE-2026-14824

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp

4.8
CVE-2026-15233

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at

4.8
CVE-2026-20198

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut

4.8
CVE-2026-13701

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o

4.8
CVE-2026-44401

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that

4.8
CVE-2026-18741

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management mod

4.8
CVE-2026-77506

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

4.8
CVE-2026-79663

Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdo

4.8
CVE-2026-26211

Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without outp

4.7
CVE-2025-9289

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sani

4.7
CVE-2025-2204

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign

4.7
CVE-2026-24771

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-S

4.7
CVE-2025-6594

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

4.7
CVE-2025-6595

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

4.7
CVE-2026-24674

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,

4.7
CVE-2026-25616

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

4.7
CVE-2025-62320

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s

4.7
CVE-2026-33311

DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4

4.7
CVE-2026-3213

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b

4.7
CVE-2026-33916

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve

4.7
CVE-2026-27599

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati

4.7
CVE-2026-34561

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati

4.7
CVE-2026-34562

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati

4.7
CVE-2026-4406

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t

4.7
CVE-2026-40301

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style

4.7
CVE-2026-5721

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor

4.7
CVE-2025-52206

ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

4.7
CVE-2026-41692

i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes.

4.7
CVE-2026-27682

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based

4.7
CVE-2026-44581

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Rou

4.7
CVE-2026-44899

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the

4.7
CVE-2026-44757

SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai

4.7
CVE-2026-2827

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati

4.7
CVE-2026-12463

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha

4.7
CVE-2026-44587

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ

4.7
CVE-2026-44760

Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave

4.7
CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus

4.7
CVE-2026-50183

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit

4.7
CVE-2026-54163

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th

4.7
CVE-2026-64823

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_

4.7
CVE-2026-3093

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1

4.7
CVE-2026-15452

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit

4.7
CVE-2026-71497

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl

4.7
CVE-2026-73490

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

4.7
CVE-2026-14287

The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated requ

4.7
CVE-2026-68921

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate optio

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started