CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vul
A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, versi
A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unkn
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown proc
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown func
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerabilit
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess
A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by th
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the
A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unkno
A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of
A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part
A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unk
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are
A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an
An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affe
A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vu
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation.
A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown par
A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function o
A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This
A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu
A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions
A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affe
A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected b
A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function
A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This i
A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This af
A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki
A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of
The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could al
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili
A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processin
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started