Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 417/793
3.5
CVE-2024-13021

A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Aff

3.5
CVE-2024-13033

A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. Affected by this

3.5
CVE-2024-13034

A vulnerability, which was classified as problematic, was found in code-projects Chat System 1.0. This affects an unknow

3.5
CVE-2024-13069

A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected

3.5
CVE-2024-13074

A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. This affects an unknown p

3.5
CVE-2024-13075

A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. This vulnerability affects unk

3.5
CVE-2024-13076

A vulnerability, which was classified as problematic, has been found in PHPGurukul Land Record System 1.0. This issue af

3.5
CVE-2024-13077

A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unk

3.5
CVE-2024-13080

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been classified as problematic. This affects an u

3.5
CVE-2024-13081

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been declared as problematic. This vulnerability

3.5
CVE-2024-13082

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as problematic. This issue affects som

3.5
CVE-2024-13083

A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown fu

3.3
CVE-2023-37531

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att

3.3
CVE-2024-6692

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr

3.3
CVE-2024-46970

In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

3.3
CVE-2024-9283

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi

3.1
CVE-2024-3178

Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanc

3.1
CVE-2024-3179

Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class

3.1
CVE-2024-3180

Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file

3.1
CVE-2024-3181

Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search F

3.1
CVE-2024-28866

GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a re

3.1
CVE-2024-25637

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not

3.1
CVE-2024-43411

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in

3.1
CVE-2024-9048

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab

3.1
CVE-2024-45099

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb

3.1
CVE-2024-42195

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H

3.0
CVE-2024-23553

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a s

3.0
CVE-2023-37529

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att

3.0
CVE-2023-37530

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att

2.9
CVE-2024-47058

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use

2.7
CVE-2024-24807

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue

2.7
CVE-2024-35239

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access

2.7
CVE-2024-37253

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi

2.6
CVE-2017-20188

A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerabili

2.6
CVE-2024-32405

Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via

2.6
CVE-2024-38364

DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institut

2.6
CVE-2024-9075

A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera

2.4
CVE-2024-0181

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected b

2.4
CVE-2024-0184

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulne

2.4
CVE-2024-0262

A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown

2.4
CVE-2024-0476

A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an un

2.4
CVE-2024-0499

A vulnerability, which was classified as problematic, has been found in SourceCodester House Rental Management System 1.

2.4
CVE-2024-0500

A vulnerability, which was classified as problematic, was found in SourceCodester House Rental Management System 1.0. Af

2.4
CVE-2024-0501

A vulnerability has been found in SourceCodester House Rental Management System 1.0 and classified as problematic. Affec

2.4
CVE-2024-0557

A vulnerability, which was classified as problematic, was found in DedeBIZ 6.3.0. This affects an unknown part of the co

2.4
CVE-2024-0718

A vulnerability, which was classified as problematic, has been found in liuwy-dlsdys zhglxt 4.7.7. This issue affects so

2.4
CVE-2016-15037

A vulnerability, which was classified as problematic, has been found in go4rayyan Scumblr up to 2.0.1a. Affected by this

2.4
CVE-2024-0948

** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue af

2.4
CVE-2024-1018

A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of

2.4
CVE-2024-1022

A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started