CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render
e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulner
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configu
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra
D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulne
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated a
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8
MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered witho
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious
immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://pl
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cros
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scrip
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unau
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 5,465 CVE records associated with CWE-79 in our database. Of these, 141 are critical severity, 1219 are high severity, and 3351 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started