CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like re
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if a
Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. Th
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa
The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back
The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to
ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 par
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bi
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checkl
resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject ar
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulne
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogCo
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vu
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.p
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.p
Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sectio
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Us
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back i
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile
The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape
The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter be
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/mode
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inje
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started