CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e
Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server si
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to imprope
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package nam
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rende
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder
Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Elect
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an
AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side
Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allo
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started