CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u
ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and
A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di
A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a cra
A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In
YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DO
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Mi
A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio
Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framewo
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scr
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file uplo
Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary co
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Ext
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln
Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3,
A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability res
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts int
Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n
Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod
Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the exec
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft
ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com
Lack of output escaping in the id attribute of menu lists.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage C
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started