CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech
An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name,
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in
Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa
Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to
A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint pre
MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inse
Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authentic
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio
A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the
UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti
UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i
Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow.
DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑gener
A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log d
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HT
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (pack
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authe
Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attack
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutr
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started