CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL an
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserLi
EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary J
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.Ap
A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM
Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced
Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a
Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass f
A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown
ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability cou
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Foru
A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part
A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn
A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown pr
A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of th
A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is
A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vu
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the fun
A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. Affected is the f
A vulnerability, which was classified as problematic, was found in code-projects Online Car Rental System 1.0. This affe
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and
Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers tha
Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a
This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filenam
This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identi
This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirec
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through
Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct
Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payloa
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverag
Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the des
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3
MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores
The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow
The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versio
Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerabili
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high p
mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by thi
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started