CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controll
Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS.
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS
Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitra
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attac
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory p
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response
The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back i
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr
The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent fo
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function a
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via th
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions
A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote
The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Tem
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view tem
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of err
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitizat
Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to injec
Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypas
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the '
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject Ja
The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via
The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started