CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authent
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting
The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the we
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0.
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all
Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel
A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, th
Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerabili
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
Dynamics 365 Sales Spoofing Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365 Field Service Spoofing Vulnerability
Dynamics 365 Sales Spoofing Vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability i
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability.
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability.
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability i
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil
Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerabl
FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified
Dynamics 365 Customer Insights Spoofing Vulnerability
Dynamics 365 Customer Insights Spoofing Vulnerability
Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management
CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected ve
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools,
Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X
WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a
The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputtin
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iMana
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.
Microsoft Dynamics 365 Sales Spoofing Vulnerability
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could re
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started