CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) S
There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allow
A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafte
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a cr
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code
Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c
Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c
A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privi
The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high priv
The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could a
A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-si
The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which coul
The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could a
The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow
The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could all
The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could a
The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow hi
Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin pan
Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 a
A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise
In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can r
The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high
The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high pri
The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission s
The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high pr
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond
The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s
A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s
The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started