CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI throu
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their d
A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (
ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was
A vulnerability has been found in khodakhah NodCMS 3.4.1 and classified as problematic. Affected by this vulnerability i
A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issu
A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issu
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affec
A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerabi
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue a
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown fu
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is a
A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affecte
A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in
A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown funct
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Busines
A vulnerability was found in app1pro Shopicial up to 20230830. It has been declared as problematic. This vulnerability a
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass aut
A vulnerability has been found in vnotex vnote up to 3.17.0 and classified as problematic. Affected by this vulnerabilit
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in your runti
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versio
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown func
A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This a
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto
An Improper neutralization of input during web page generation in the Schweitzer Engineering Laboratories SEL-411L could
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the Schweitzer Engineering L
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as problematic
A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problema
A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issu
Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbr
A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected b
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML inje
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web
A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unk
A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unkn
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affec
Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticate
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 ve
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versio
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may all
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions sta
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswe
matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected vers
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started