CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. S
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications
Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc
The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow h
The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p
Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system.
Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that m
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below
There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a rem
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery set
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scriptin
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v
Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attac
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenti
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP param
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't pr
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ O
Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the
Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload i
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started