Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 419/793
2.4
CVE-2024-7815

A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affecte

2.4
CVE-2024-7900

A vulnerability, which was classified as problematic, was found in xiaohe4966 TpMeCMS 1.3.3.2. Affected is an unknown fu

2.4
CVE-2024-8084

A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0.

2.4
CVE-2024-8145

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unk

2.4
CVE-2024-8693

A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is s

2.4
CVE-2024-9083

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects

2.4
CVE-2024-9279

A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown

2.4
CVE-2024-9792

A vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the

2.4
CVE-2024-9807

A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some

2.4
CVE-2024-9856

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this

2.4
CVE-2024-9952

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so

2.4
CVE-2024-10197

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affect

2.4
CVE-2024-10198

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as problematic. Affected

2.4
CVE-2024-10199

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by

2.4
CVE-2024-10414

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an

2.4
CVE-2024-10477

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknow

2.4
CVE-2024-10478

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affec

2.4
CVE-2024-10479

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknow

2.4
CVE-2024-10806

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner

2.4
CVE-2024-10807

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff

2.4
CVE-2024-10840

A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function

2.4
CVE-2024-10842

A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this is

2.4
CVE-2024-11130

A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown

2.4
CVE-2024-12503

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functi

2.4
CVE-2024-12893

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this

2.4
CVE-2024-12982

A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affe

2.4
CVE-2024-12983

A vulnerability classified as problematic has been found in code-projects Hospital Management System 1.0. This affects a

2.4
CVE-2024-13013

A vulnerability, which was classified as problematic, was found in PHPGurukul Maid Hiring Management System 1.0. Affecte

2.4
CVE-2024-13015

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. Affected by thi

2.4
CVE-2024-13017

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been declared as problematic. This vul

2.4
CVE-2024-13018

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been rated as problematic. This issue

2.4
CVE-2024-13023

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. This vulne

2.4
CVE-2024-13031

A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown fun

2.2
CVE-2024-2179

Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insuff

2.0
CVE-2024-1247

Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient val

2.0
CVE-2024-1246

Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie

2.0
CVE-2023-45706

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit th

2.0
CVE-2024-2753

Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar co

1.8
CVE-2024-22477

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained

0.0
CVE-2024-22213

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N

CVE-2024-5420

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec

CVE-2024-5961

Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cros

CVE-2024-22168

A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found

CVE-2024-3798

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project

CVE-2024-6886

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea

0.0
CVE-2024-43359

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting

CVE-2024-2259

This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo

CVE-2022-26328

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Pe

CVE-2024-7427

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ N

CVE-2024-7873

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started