Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 279/793
8.0
CVE-2024-52951

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authent

8.0
CVE-2024-54003

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting

7.9
CVE-2024-29000

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the we

7.9
CVE-2024-54139

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0.

7.8
CVE-2023-25365

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the

7.8
CVE-2024-37063

A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all

7.7
CVE-2024-30248

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel

7.7
CVE-2024-7047

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior

7.7
CVE-2024-6379

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release

7.7
CVE-2024-45594

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj

7.7
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote

7.7
CVE-2024-52595

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, th

7.6
CVE-2024-21637

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerabili

7.6
CVE-2024-22130

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107

7.6
CVE-2024-21327

Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

7.6
CVE-2024-21328

Dynamics 365 Sales Spoofing Vulnerability

7.6
CVE-2024-21389

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.6
CVE-2024-21393

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.6
CVE-2024-21394

Dynamics 365 Field Service Spoofing Vulnerability

7.6
CVE-2024-21396

Dynamics 365 Sales Spoofing Vulnerability

7.6
CVE-2024-24906

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability i

7.6
CVE-2024-24904

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability.

7.6
CVE-2024-24905

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability.

7.6
CVE-2024-24907

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability i

7.6
CVE-2024-21419

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.6
CVE-2024-28434

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil

7.6
CVE-2024-29504

Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code

7.6
CVE-2024-4336

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti

7.6
CVE-2024-4337

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti

7.6
CVE-2024-27082

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerabl

7.6
CVE-2024-34697

FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified

7.6
CVE-2024-30047

Dynamics 365 Customer Insights Spoofing Vulnerability

7.6
CVE-2024-30048

Dynamics 365 Customer Insights Spoofing Vulnerability

7.6
CVE-2024-2301

Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management

7.6
CVE-2024-36109

CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected ve

7.6
CVE-2024-35266

Azure DevOps Server Spoofing Vulnerability

7.6
CVE-2024-35267

Azure DevOps Server Spoofing Vulnerability

7.6
CVE-2024-41959

mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja

7.6
CVE-2024-39403

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting

7.6
CVE-2024-43805

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit

7.6
CVE-2024-43476

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.6
CVE-2021-27915

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic

7.6
CVE-2024-42346

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools,

7.6
CVE-2024-9198

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X

7.6
CVE-2024-47782

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a

7.6
CVE-2024-5429

The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputtin

7.6
CVE-2020-11859

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iMana

7.6
CVE-2022-26324

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

7.6
CVE-2024-49053

Microsoft Dynamics 365 Sales Spoofing Vulnerability

7.5
CVE-2023-6123

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could re

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started