CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute ar
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.p
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/i
A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attac
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billin
CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin use
The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which
The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before
The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attri
The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes
Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which cou
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which coul
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before out
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t
Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input san
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to stea
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal
Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run ar
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyrigh
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping functio
Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attack
Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary
Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote
Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows
Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to r
Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote a
Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrar
Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user nam
Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before
The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes befo
The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outp
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape
The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior t
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri
Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent,
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II")
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started