CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability a
ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTM
The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an un
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasti
Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamic
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0,
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability cou
auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Pri
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli
An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not de
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Acc
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdo
Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prio
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Script
The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before o
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a pa
SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are expo
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities
The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanit
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin
CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rend
Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Script
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS)
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/author
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command ca
@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend cl
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability tha
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users'
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c
Potential Cross-Site Scripting (XSS) in the page editing area.
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-si
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering
FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been iden
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back'
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility tha
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScri
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Aut
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started