Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 398/793
4.8
CVE-2024-8660

Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. S

4.8
CVE-2022-25774

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications

4.8
CVE-2024-37879

Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato

4.8
CVE-2024-46654

A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at

4.8
CVE-2024-45793

Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll

4.8
CVE-2024-8758

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which

4.8
CVE-2024-8291

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A

4.8
CVE-2024-7878

The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-46333

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc

4.8
CVE-2024-3635

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow h

4.8
CVE-2024-8283

The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8457

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,

4.8
CVE-2024-46475

A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at

4.8
CVE-2024-45073

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p

4.8
CVE-2024-31835

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi

4.8
CVE-2024-47528

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach

4.8
CVE-2024-45960

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system.

4.8
CVE-2024-45964

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

4.8
CVE-2024-25694

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that m

4.8
CVE-2024-25701

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11

4.8
CVE-2024-25702

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below

4.8
CVE-2024-25707

There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a rem

4.8
CVE-2024-47840

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed

4.8
CVE-2024-45932

Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz

4.8
CVE-2024-46410

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the

4.8
CVE-2024-5968

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery set

4.8
CVE-2024-45127

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scriptin

4.8
CVE-2024-46980

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1

4.8
CVE-2024-45714

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v

4.8
CVE-2024-49392

Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro

4.8
CVE-2024-30159

A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attac

4.8
CVE-2024-30160

A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenti

4.8
CVE-2024-46240

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co

4.8
CVE-2024-46538

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v

4.8
CVE-2024-48652

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont

4.8
CVE-2024-48656

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker

4.8
CVE-2024-20264

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20269

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20298

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20300

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20364

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20386

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20403

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20409

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-20415

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

4.8
CVE-2024-48233

mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP param

4.8
CVE-2024-48239

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't pr

4.8
CVE-2024-5532

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ O

4.8
CVE-2024-51506

Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the

4.8
CVE-2024-51507

Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload i

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started