CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user i
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe
Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans
Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp
A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with li
Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in
Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions
Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol
Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio
Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the
FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 co
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported co
AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occu
AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedde
AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By
The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar
CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar
A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could al
A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS ge
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authe
Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute a
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started