CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Aff
A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. Affected by this
A vulnerability, which was classified as problematic, was found in code-projects Chat System 1.0. This affects an unknow
A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected
A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. This affects an unknown p
A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. This vulnerability affects unk
A vulnerability, which was classified as problematic, has been found in PHPGurukul Land Record System 1.0. This issue af
A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unk
A vulnerability was found in PHPGurukul Land Record System 1.0. It has been classified as problematic. This affects an u
A vulnerability was found in PHPGurukul Land Record System 1.0. It has been declared as problematic. This vulnerability
A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as problematic. This issue affects som
A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown fu
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi
Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanc
Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class
Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file
Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search F
GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a re
October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a s
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use
Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi
A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerabili
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via
DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institut
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected b
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulne
A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown
A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an un
A vulnerability, which was classified as problematic, has been found in SourceCodester House Rental Management System 1.
A vulnerability, which was classified as problematic, was found in SourceCodester House Rental Management System 1.0. Af
A vulnerability has been found in SourceCodester House Rental Management System 1.0 and classified as problematic. Affec
A vulnerability, which was classified as problematic, was found in DedeBIZ 6.3.0. This affects an unknown part of the co
A vulnerability, which was classified as problematic, has been found in liuwy-dlsdys zhglxt 4.7.7. This issue affects so
A vulnerability, which was classified as problematic, has been found in go4rayyan Scumblr up to 2.0.1a. Affected by this
** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue af
A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of
A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started