CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result i
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 ver
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allow
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime en
Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.5 versions.
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output i
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin
Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9,
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject
A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is a
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is so
A vulnerability was found in kirill2485 TekNet. It has been classified as problematic. Affected is an unknown function o
A vulnerability has been found in stiiv contact_app and classified as problematic. Affected by this vulnerability is the
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM and classified as problematic. Affected by
A vulnerability classified as problematic was found in Jobs-Plugin. Affected by this vulnerability is an unknown functio
A vulnerability was found in ahmyi RivetTracker. It has been declared as problematic. Affected by this vulnerability is
A vulnerability, which was classified as problematic, has been found in ahmyi RivetTracker. This issue affects some unkn
A vulnerability, which was classified as problematic, has been found in kkokko NeoXplora. Affected by this issue is some
A vulnerability was found in oxguy3 coebot-www and classified as problematic. This issue affects the function displayCha
A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3.
A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unkno
A vulnerability was found in Kaltura mwEmbed up to 2.96.rc1 and classified as problematic. This issue affects some unkno
A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown fu
A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. Affected by this vulner
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-uc
A vulnerability was found in OSM Lab show-me-the-way. It has been rated as problematic. This issue affects some unknown
A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as
A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects s
A vulnerability has been found in snoyberg keter up to 1.8.1 and classified as problematic. This vulnerability affects u
A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects
A vulnerability has been found in jamesmartin Inline SVG up to 1.7.1 and classified as problematic. Affected by this vul
A vulnerability was found in ritterim definely. It has been classified as problematic. Affected is an unknown function o
A vulnerability has been found in ss15-this-is-sparta and classified as problematic. This vulnerability affects unknown
A vulnerability, which was classified as problematic, has been found in 01-Scripts 01ACP. This issue affects some unknow
A vulnerability has been found in yanheven console and classified as problematic. Affected by this vulnerability is the
A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects
A vulnerability was found in HealthMateWeb. It has been declared as problematic. Affected by this vulnerability is an un
A vulnerability was found in 01-Scripts 01-Artikelsystem. It has been classified as problematic. Affected is an unknown
A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is t
A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerabil
A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown f
A vulnerability has been found in manikandan170890 php-form-builder-class and classified as problematic. Affected by thi
A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some u
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started