CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible becau
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging e
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not s
Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prio
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U run
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-tran
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vu
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo
@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Vers
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An a
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacke
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user
Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthentic
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potenti
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte ha
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C
The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fie
The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileg
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote a
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extens
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed re
The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule
PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cros
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiP
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects
The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scriptin
dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i
Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started