CWE-79


Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.


We have discovered 18,256,672 live websites that are affected by CWE-79.

Contact us to get more info









CVEs

  • Count - 6,067



Website Distribution by Country

Number of websites using CWE-79
United States5,718,470 websites



Germany1,837,361 websites
Japan947,067 websites
France894,215 websites
Russia706,918 websites
GB697,029 websites
Netherlands598,619 websites
Italy571,586 websites
Poland383,371 websites
Spain346,927 websites

Website Distribution by TLD

Number of websites using CWE-79
.com7,724,610 websites
.de1,177,445 websites
.org824,366 websites
.ru587,660 websites
.net564,406 websites
.nl516,498 websites
.co.uk444,918 websites
.it423,453 websites
.fr374,347 websites
.pl297,443 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-79
DiscoveredCVEDescriptionWebsites
Aug, 2026CVE-2026-13416 CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia672
Aug, 2026CVE-2026-78261 WordPress Realtyna Organic IDX plugin plugin <= 5.4.1 - Cross Site Scripting (XSS) vulnerability1
Aug, 2026CVE-2026-78281 WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability113
Aug, 2026CVE-2026-78283 WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability92
Aug, 2026CVE-2026-78289 WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability35
Aug, 2026CVE-2026-78333 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log66
Aug, 2026CVE-2026-2388 Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes7
Aug, 2026CVE-2026-3002 Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks3,161
Aug, 2026CVE-2026-5092 Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI165
Aug, 2026CVE-2026-6178 Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode69,409
List of the most common CVEs that are part of CWE-79
DiscoveredCVEDescriptionWebsites
Aug, 2026CVE-2026-64638 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a spec...7,982,646
Apr, 2020CVE-2020-11023 Potential XSS vulnerability in jQuery6,513,294
Jul, 2026CVE-2026-15425 Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)3,621,302
Apr, 2020CVE-2020-11022 jQuery has a potential XSS vulnerability3,294,540
Mar, 2026CVE-2026-3427 Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute1,958,120
Jun, 2026CVE-2026-29170 Apache HTTP Server: mod_proxy_ftp XSS1,899,319
Feb, 2026CVE-2026-1293 Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute1,756,732
May, 2026CVE-2026-6127 Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API1,389,801
Jan, 2022CVE-2022-21662 Stored XSS in WordPress1,269,288
Sep, 2021CVE-2021-39202 WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget1,256,275

Websites affected by CWE-79

Top websites that are affected by CWE-79. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org United States*
**********.com United States**
**********.***********.com United States**
********.****.br Brazil**
******.com United States**
*********.com United States**
********.*********.com United States**
*********.com United States***
*******.com Singapore***
***********.com Ireland***
See full domain list