CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagn
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Script
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulne
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 1
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) ren
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lu
SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName,
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated use
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in a
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger re
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendere
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing val
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) r
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() metho
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS C
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stor
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to s
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file ass
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbi
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen
Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started