Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 252/793
4.3
CVE-2025-2354

A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vul

4.3
CVE-2025-2361

A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability

4.3
CVE-2021-26087

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, versi

4.3
CVE-2025-2709

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unkn

4.3
CVE-2025-2710

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown proc

4.3
CVE-2025-2711

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown func

4.3
CVE-2025-2712

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerabilit

4.3
CVE-2025-2714

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is

4.3
CVE-2025-25001

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

4.3
CVE-2025-3388

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects

4.3
CVE-2025-3397

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess

4.3
CVE-2025-3489

A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by th

4.3
CVE-2025-3531

A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file

4.3
CVE-2025-3532

A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the

4.3
CVE-2025-3533

A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unkno

4.3
CVE-2025-3554

A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of

4.3
CVE-2025-3612

A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part

4.3
CVE-2025-4075

A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unk

4.3
CVE-2025-46549

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at

4.3
CVE-2025-46550

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are

4.3
CVE-2025-4512

A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an

4.3
CVE-2025-46749

An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ

4.3
CVE-2025-46786

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc

4.3
CVE-2025-4862

A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affe

4.3
CVE-2025-4939

A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vu

4.3
CVE-2025-41228

VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. 

4.3
CVE-2025-5013

A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown par

4.3
CVE-2025-5133

A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function o

4.3
CVE-2025-5177

A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This

4.3
CVE-2025-5377

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu

4.3
CVE-2025-5378

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown

4.3
CVE-2024-3509

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insu

4.3
CVE-2025-20297

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2

4.3
CVE-2025-41437

Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions

4.3
CVE-2025-5975

A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affe

4.3
CVE-2025-6092

A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this

4.3
CVE-2025-6126

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected b

4.3
CVE-2025-6268

A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function

4.3
CVE-2025-6285

A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This i

4.3
CVE-2025-6473

A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This af

4.3
CVE-2025-6569

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu

4.3
CVE-2025-5682

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki

4.3
CVE-2025-6700

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of

4.3
CVE-2025-5730

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could al

4.3
CVE-2025-7182

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A

4.3
CVE-2025-49540

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili

4.3
CVE-2025-49541

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili

4.3
CVE-2025-49543

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili

4.3
CVE-2025-7567

A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processin

4.3
CVE-2025-7672

The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started