CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b
A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifi
A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of
A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the fi
A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /ap
A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/m
A vulnerability was determined in WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3. The affected element is
A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.
A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown fu
A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality
A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdoc
A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown functio
A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /ap
A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet
A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of
A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unk
A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerabil
A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. T
A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects
A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is
A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is a
A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the fi
A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File
A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the
A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file
A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php
A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin
A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of t
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflec
A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set
A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo
A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process
A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerabili
A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown func
A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI.
A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functional
A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unkno
A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen
changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha
A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of t
OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming
A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file
A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032
A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/
A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/
A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of th
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started