CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In v
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page
laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP messa
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in ve
The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field par
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possi
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testi
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS T
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly handle the input
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not handle uploaded files corr
ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching
NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromis
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology tha
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated mal
OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, t
OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticat
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when usi
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall old
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sopho
SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stea
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipu
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML c
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Track
Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript
Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Arche
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPr
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate input in
Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subje
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started