CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote a
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an at
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable
An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker cou
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo
The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored
A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode u
A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode u
A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode u
A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode u
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-cont
Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerab
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes th
SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` param
An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and
The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino
Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them
Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cros
GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting vi
GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cro
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute Java
Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Gra
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
The Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS prote
An issue was discovered in WeCube platform 3.2.2. A DOM XSS vulnerability has been found on the plugin database executio
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting
Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X
ViewVC, a browser interface for CVS and Subversion version control repositories, as a cross-site scripting vulnerability
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnera
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary w
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbit
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execut
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started