Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 574/793
4.1
CVE-2022-36390

Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar pl

4.1
CVE-2022-37338

Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <

4.1
CVE-2022-37339

Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 a

4.1
CVE-2022-40213

Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin

4.1
CVE-2022-40204

A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via t

4.0
CVE-2021-46676

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2021-46677

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2021-46678

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2021-46679

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2021-46680

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2021-46681

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu

4.0
CVE-2022-3895

Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output

4.0
CVE-2022-40680

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.1

3.9
CVE-2022-29817

In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible

3.8
CVE-2022-0473

OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular

3.8
CVE-2022-25620

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Pr

3.8
CVE-2022-2256

A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla

3.8
CVE-2022-30297

Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable

3.7
CVE-2022-24917

An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other

3.7
CVE-2022-24918

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other us

3.7
CVE-2022-24919

An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other u

3.7
CVE-2022-29929

In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

3.7
CVE-2022-35229

An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o

3.7
CVE-2022-35230

An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe

3.5
CVE-2021-4035

A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of

3.5
CVE-2022-0475

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code cou

3.5
CVE-2022-1075

A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue

3.5
CVE-2022-1085

A vulnerability was found in CLTPHP up to 6.0. It has been declared as problematic. Affected by this vulnerability is th

3.5
CVE-2022-1086

A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Ma

3.5
CVE-2022-1087

A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profil

3.5
CVE-2022-1180

Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

3.5
CVE-2022-1503

A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the fil

3.5
CVE-2022-1526

A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST paramete

3.5
CVE-2022-1536

A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Das

3.5
CVE-2022-1590

A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint

3.5
CVE-2022-1816

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issu

3.5
CVE-2022-1817

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the

3.5
CVE-2021-4231

A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the

3.5
CVE-2021-4232

A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function o

3.5
CVE-2022-1979

A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulner

3.5
CVE-2022-1991

A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.p

3.5
CVE-2020-36523

A vulnerability was found in PlantUML 6.43. It has been declared as problematic. Affected by this vulnerability is the c

3.5
CVE-2020-36524

A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown f

3.5
CVE-2020-36525

A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New W

3.5
CVE-2020-36526

A vulnerability classified as problematic was found in Countdown Timer. This vulnerability affects unknown code of the c

3.5
CVE-2020-36527

A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown p

3.5
CVE-2020-36544

A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of

3.5
CVE-2019-25070

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. Th

3.5
CVE-2017-20034

A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the fil

3.5
CVE-2017-20035

A vulnerability, which was classified as problematic, has been found in PHPList 3.2.6. This issue affects some unknown p

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started