Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 262/793
3.5
CVE-2025-9233

A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_

3.5
CVE-2025-9234

A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file mainten

3.5
CVE-2025-9235

A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_event

3.5
CVE-2025-9237

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_

3.5
CVE-2025-9306

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown

3.5
CVE-2025-9388

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm.

3.5
CVE-2025-9407

A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file

3.5
CVE-2025-9429

A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the fi

3.5
CVE-2025-9590

A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerabil

3.5
CVE-2025-9646

A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organ

3.5
CVE-2025-9652

A vulnerability was determined in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /intranet/

3.5
CVE-2025-9653

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona

3.5
CVE-2025-9655

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble

3.5
CVE-2025-9657

A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_c

3.5
CVE-2025-9658

A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/ja

3.5
CVE-2025-9659

A vulnerability has been found in O2OA up to 10.0-410. The affected element is an unknown function of the file /x_portal

3.5
CVE-2025-9680

A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_des

3.5
CVE-2025-9681

A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent

3.5
CVE-2025-9682

A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the

3.5
CVE-2025-9683

A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_cm

3.5
CVE-2025-9715

A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_cms_assemble_control/ja

3.5
CVE-2025-9716

A vulnerability was determined in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the

3.5
CVE-2025-9717

A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file

3.5
CVE-2025-9718

A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_

3.5
CVE-2025-9719

A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processpla

3.5
CVE-2025-9720

A vulnerability was detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Tabe

3.5
CVE-2025-9721

A flaw has been found in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module

3.5
CVE-2025-9722

A vulnerability has been found in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the fil

3.5
CVE-2025-9723

A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educ

3.5
CVE-2025-9724

A vulnerability was determined in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /intranet

3.5
CVE-2025-9734

A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_q

3.5
CVE-2025-9735

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_de

3.5
CVE-2025-9736

A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query

3.5
CVE-2025-9737

A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_desig

3.5
CVE-2025-9738

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of t

3.5
CVE-2025-9754

A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of

3.5
CVE-2025-9796

A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/

3.5
CVE-2025-9834

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /reg

3.5
CVE-2025-9845

A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an u

3.5
CVE-2025-9939

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an un

3.5
CVE-2025-9940

A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the fil

3.5
CVE-2025-10026

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown fun

3.5
CVE-2025-10027

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func

3.5
CVE-2025-10028

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /i

3.5
CVE-2025-10029

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown cod

3.5
CVE-2025-10074

A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the fil

3.5
CVE-2025-10075

A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown func

3.5
CVE-2025-10088

A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file

3.5
CVE-2025-10117

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi

3.5
CVE-2025-9111

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started