Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 261/793
3.5
CVE-2025-7942

A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by

3.5
CVE-2025-7951

A vulnerability classified as problematic has been found in code-projects Public Chat Room 1.0. This affects an unknown

3.5
CVE-2025-8115

A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by

3.5
CVE-2025-8155

A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability

3.5
CVE-2025-8167

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by

3.5
CVE-2025-8191

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown f

3.5
CVE-2025-8211

A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is t

3.5
CVE-2025-8222

A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c

3.5
CVE-2025-8365

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerabili

3.5
CVE-2025-8380

A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability

3.5
CVE-2025-37108

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

3.5
CVE-2025-37109

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

3.5
CVE-2025-8501

A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected

3.5
CVE-2025-8506

A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problema

3.5
CVE-2025-8507

A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown func

3.5
CVE-2025-8508

A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerabilit

3.5
CVE-2025-8509

A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u

3.5
CVE-2025-8510

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of

3.5
CVE-2025-8511

A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown cod

3.5
CVE-2025-8535

A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects

3.5
CVE-2025-8551

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u

3.5
CVE-2025-8555

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct

3.5
CVE-2025-8743

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. This affects an unknown part of the

3.5
CVE-2025-8765

A vulnerability classified as problematic was found in Datacom DM955 5GT 1200 825.8010.00. Affected by this vulnerabilit

3.5
CVE-2025-8784

A vulnerability classified as problematic was found in Portabilis i-Educar up to 2.9. This vulnerability affects unknown

3.5
CVE-2025-8785

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. This issue affect

3.5
CVE-2025-8786

A vulnerability, which was classified as problematic, was found in Portabilis i-Diario up to 1.5.0. Affected is an unkno

3.5
CVE-2025-8787

A vulnerability has been found in Portabilis i-Diario up to 1.5.0 and classified as problematic. Affected by this vulner

3.5
CVE-2025-8788

A vulnerability was found in Portabilis i-Diario up to 1.5.0 and classified as problematic. Affected by this issue is so

3.5
CVE-2025-8847

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the

3.5
CVE-2025-8975

A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/cont

3.5
CVE-2025-8976

A vulnerability has been found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin1

3.5
CVE-2025-9003

A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.ph

3.5
CVE-2025-9095

A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the

3.5
CVE-2025-9096

A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the l

3.5
CVE-2025-9101

A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file

3.5
CVE-2025-9104

A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /plano

3.5
CVE-2025-9105

A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the fi

3.5
CVE-2025-9106

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-en

3.5
CVE-2025-9137

A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm.

3.5
CVE-2025-9138

A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Perform

3.5
CVE-2025-9143

A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. T

3.5
CVE-2025-9144

A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.

3.5
CVE-2025-9145

A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file

3.5
CVE-2025-9147

A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el

3.5
CVE-2025-9167

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice

3.5
CVE-2025-9168

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice o

3.5
CVE-2025-9169

A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the c

3.5
CVE-2025-9170

A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax

3.5
CVE-2025-9171

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started