Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 414/793
3.5
CVE-2024-43809

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

3.5
CVE-2024-7901

A vulnerability has been found in Scada-LTS 2.7.8 and classified as problematic. Affected by this vulnerability is an un

3.5
CVE-2024-7914

A vulnerability classified as problematic has been found in SourceCodester Yoga Class Registration System 1.0. Affected

3.5
CVE-2024-7916

A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affecte

3.5
CVE-2024-7942

A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerabilit

3.5
CVE-2024-7945

A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. A

3.5
CVE-2024-7948

A vulnerability classified as problematic was found in SourceCodester Accounts Manager App 1.0. This vulnerability affec

3.5
CVE-2024-8022

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This

3.5
CVE-2024-8136

A vulnerability, which was classified as problematic, was found in SourceCodester Record Management System 1.0. This aff

3.5
CVE-2024-8137

A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as problematic. This vulner

3.5
CVE-2024-8140

A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this is

3.5
CVE-2024-8141

A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. T

3.5
CVE-2024-8142

A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. Thi

3.5
CVE-2024-8144

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functi

3.5
CVE-2024-8151

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This

3.5
CVE-2024-8152

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulne

3.5
CVE-2024-8153

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue af

3.5
CVE-2024-8154

A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an u

3.5
CVE-2024-8172

A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. Th

3.5
CVE-2024-8208

A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic

3.5
CVE-2024-8209

A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Aff

3.5
CVE-2024-8337

A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VC

3.5
CVE-2024-44918

A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to exe

3.5
CVE-2024-8370

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the

3.5
CVE-2024-43413

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr

3.5
CVE-2024-8407

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p

3.5
CVE-2024-8411

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int

3.5
CVE-2024-6792

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public p

3.5
CVE-2024-27125

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a

3.5
CVE-2024-8554

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is

3.5
CVE-2024-8562

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some u

3.5
CVE-2024-8563

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown

3.5
CVE-2024-8572

A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affect

3.5
CVE-2024-8582

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected

3.5
CVE-2024-8583

A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It ha

3.5
CVE-2024-8610

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe

3.5
CVE-2024-8708

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. T

3.5
CVE-2024-8783

A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown funct

3.5
CVE-2024-8863

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dan

3.5
CVE-2024-8867

A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown c

3.5
CVE-2024-8951

A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu

3.5
CVE-2024-9007

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of

3.5
CVE-2024-9030

A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod

3.5
CVE-2024-9031

A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe

3.5
CVE-2024-9033

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic.

3.5
CVE-2024-9077

A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A

3.5
CVE-2024-9084

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u

3.5
CVE-2024-9089

A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue

3.5
CVE-2024-9092

A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble

3.5
CVE-2024-9276

A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started