Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-79'

View all threats tagged with 'cwe-79'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-79

Threats Tagged 'cwe-79'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-2357: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in boldthemes Bold Page BuilderCVE-2026-2357
0

The Bold Page Builder plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in its 'bt_bb_shortcode' shortcode. This vulnerability affects all versions up to and including 5.6.8 and arises from insufficient input sanitization and output escaping of user-supplied attributes. Authenticated users with contributor-level access or higher can exploit this flaw to inject arbitrary scripts that execute when other users view the affected pages. The vulnerability has a CVSS score of 6.4, indicating medium severity. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-13424: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ladela Online Scheduling and Appointment Booking System – BooklyCVE-2026-13424
0

The Online Scheduling and Appointment Booking System – Bookly WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in the bookly_speed_up_update_addons AJAX action. This vulnerability affects all versions up to and including 27.7 and allows unauthenticated attackers to inject arbitrary scripts that execute when an administrator views the Diagnostics → Logs page. The flaw arises from insufficient input sanitization and output escaping in an AJAX action accessible without authentication.

Join the discussion
CVE-2026-10734: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in infility Infility GlobalCVE-2026-10734
0

The Infility Global WordPress plugin is affected by a stored cross-site scripting (XSS) vulnerability in the /cf7_record log endpoint. This vulnerability allows unauthenticated attackers to inject malicious scripts that execute when any authenticated user, including those with minimal privileges, views the affected page. The issue arises from insufficient input sanitization and output escaping in all versions up to and including 2.15.21.

Join the discussion
CVE-2026-19712: CWE-79 Cross-Site Scripting (XSS) in Masteriyo LMSCVE-2026-19712
0

CVE-2026-19712 is a stored Cross-Site Scripting (XSS) vulnerability in the Masteriyo LMS WordPress plugin before version 2.3.3. The vulnerability arises because the plugin does not sanitize or escape a quiz field before outputting it, and the instructor role can store unfiltered HTML. This allows instructors to execute stored XSS attacks against any visitor of the affected page, including administrators. The issue affects default single-site installations but not multisite setups or sites that define DISALLOW_UNFILTERED_HTML.

Join the discussion
CVE-2026-13712: CWE-79 Cross-Site Scripting (XSS) in DiviCVE-2026-13712
0

CVE-2026-13712 is a Cross-Site Scripting (XSS) vulnerability in the Divi WordPress theme before version 5.9.0. It occurs because the Social Media Follow module settings are not properly escaped before being output in link attributes. This allows users with contributor-level roles to inject JavaScript that executes when higher privileged users, such as administrators, view the affected post.

Join the discussion
CVE-2026-18402: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in brainstormforce SureDash – Community, Courses & Member DashboardCVE-2026-18402
0

SureDash – Community, Courses & Member Dashboard WordPress plugin versions up to 1.10.3 are vulnerable to stored cross-site scripting (XSS) via the 'draweropenverposition' block/shortcode attribute. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and lack of proper escaping on output, allowing injection of arbitrary HTML event handlers through a crafted payload stored in block-delimiter HTML comment JSON.

Join the discussion
CVE-2026-16775: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in smub Smash Balloon Social Post Feed – Simple Social Feeds for WordPressCVE-2026-16775
0

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin is affected by a stored cross-site scripting (XSS) vulnerability via the 'id' shortcode attribute in all versions up to and including 4.9.0. This vulnerability allows authenticated users with contributor-level access or higher to inject malicious scripts that execute when other users view the affected pages. The vulnerability arises from insufficient input sanitization and output escaping.

Join the discussion
CVE-2026-16758: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in aliakro Snippet ShortcodesCVE-2026-16758
0

The Snippet Shortcodes plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in all versions up to and including 5.2.0. This vulnerability arises from insufficient input sanitization and output escaping of shortcode attributes, allowing authenticated users with contributor-level access or higher to inject arbitrary scripts. These scripts execute whenever a user views the affected page, potentially compromising user data or session integrity.

Join the discussion
CVE-2026-15790: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in emarket-design Video Gallery – YouTube Gallery, Playlist & Video GridCVE-2026-15790
0

The Youtube Showcase plugin for WordPress (Video Gallery – YouTube Gallery, Playlist & Video Grid) contains a stored cross-site scripting (XSS) vulnerability in versions up to and including 4.0.4. This vulnerability arises from insufficient sanitization and escaping of attachment titles used in shortcode image fields, allowing authenticated users with author-level access or higher to inject arbitrary scripts. The vulnerability has a CVSS score of 6.4, indicating medium severity.

Join the discussion
CVE-2026-15604: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in toocheke Toocheke CompanionCVE-2026-15604
0

The Toocheke Companion WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in versions up to and including 2.10. The flaw arises from improper input sanitization and output escaping of the 'series_bg_color' post meta field, allowing authenticated users with contributor-level access or higher to inject malicious scripts. These scripts execute when an administrator views the series list table in the WordPress admin dashboard.

Join the discussion

Showing 1 to 10 of 516 results

Filters:Tag: cwe-79
Page 1 of 52
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses