CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the f
A vulnerability, which was classified as problematic, was found in SourceCodester AC Repair and Services System 1.0. Aff
A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknow
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin
A vulnerability classified as problematic was found in SourceCodester Best Courier Management System 1.0. This vulnerabi
A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Courier Management System 1.
A vulnerability, which was classified as problematic, was found in Online Banquet Booking System 1.0. Affected is an unk
A vulnerability has been found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this vuln
A vulnerability was found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this issue is
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln
A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is a
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by thi
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this i
A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unkno
A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects
A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issu
A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an
A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCr
A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma
A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect
A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been declared as problematic. This
Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an u
A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by
A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Af
A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affec
A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul
A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown fun
A vulnerability was found in SourceCodester Book Borrower System 1.0 and classified as problematic. This issue affects s
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic.
A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0
A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. A
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unkno
A vulnerability, which was classified as problematic, was found in SourceCodester Online Quiz System 1.0. This affects a
A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vul
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. This iss
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started