Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 577/793
3.5
CVE-2022-4455

A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index

3.5
CVE-2022-4456

A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code.

3.5
CVE-2022-4495

A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue

3.5
CVE-2022-4513

A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This

3.5
CVE-2022-4514

A vulnerability, which was classified as problematic, was found in Opencaching Deutschland oc-server3. Affected is an un

3.5
CVE-2022-4520

A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue

3.5
CVE-2022-4521

A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown pa

3.5
CVE-2022-4523

A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processi

3.5
CVE-2022-4524

A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the functi

3.5
CVE-2022-4525

A vulnerability has been found in National Sleep Research Resource sleepdata.org up to 58.x and classified as problemati

3.5
CVE-2022-4526

A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is som

3.5
CVE-2022-4527

A vulnerability was found in collective.task up to 3.0.8. It has been classified as problematic. This affects the functi

3.5
CVE-2022-4560

A vulnerability was found in Joget up to 7.0.31. It has been rated as problematic. This issue affects the function getIn

3.5
CVE-2022-4585

A vulnerability classified as problematic has been found in Opencaching Deutschland oc-server3. This affects an unknown

3.5
CVE-2022-4586

A vulnerability classified as problematic was found in Opencaching Deutschland oc-server3. This vulnerability affects un

3.5
CVE-2022-4590

A vulnerability was found in mschaef toto up to 1.4.20. It has been classified as problematic. This affects an unknown p

3.5
CVE-2022-4591

A vulnerability was found in mschaef toto up to 1.4.20. It has been declared as problematic. This vulnerability affects

3.5
CVE-2022-4593

A vulnerability was found in retra-system. It has been classified as problematic. Affected is an unknown function. The m

3.5
CVE-2022-4597

A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown funct

3.5
CVE-2022-4598

A vulnerability has been found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this vulnerability

3.5
CVE-2022-4599

A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unkno

3.5
CVE-2022-4600

A vulnerability was found in Shoplazza LifeStyle 1.1. It has been classified as problematic. This affects an unknown par

3.5
CVE-2022-4601

A vulnerability was found in Shoplazza LifeStyle 1.1. It has been declared as problematic. This vulnerability affects un

3.5
CVE-2022-4602

A vulnerability was found in Shoplazza LifeStyle 1.1. It has been rated as problematic. This issue affects some unknown

3.5
CVE-2021-4256

A vulnerability was found in ctrlo lenio. It has been classified as problematic. This affects an unknown part of the fil

3.5
CVE-2021-4257

A vulnerability was found in ctrlo lenio. It has been declared as problematic. This vulnerability affects unknown code o

3.5
CVE-2022-3877

A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser

3.5
CVE-2020-36621

A vulnerability, which was classified as problematic, has been found in chedabob whatismyudid. Affected by this issue is

3.5
CVE-2021-4263

A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function d

3.5
CVE-2021-4265

A vulnerability was found in siwapp-ror. It has been rated as problematic. This issue affects some unknown processing. T

3.5
CVE-2021-4266

A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown func

3.5
CVE-2021-4267

A vulnerability classified as problematic was found in tad_discuss. Affected by this vulnerability is an unknown functio

3.5
CVE-2021-4269

A vulnerability has been found in SimpleRisk and classified as problematic. This vulnerability affects the function chec

3.5
CVE-2021-4270

A vulnerability was found in Imprint CMS. It has been classified as problematic. Affected is the function SearchForm of

3.5
CVE-2021-4271

A vulnerability was found in panicsteve w2wiki. It has been rated as problematic. Affected by this issue is the function

3.5
CVE-2021-4272

A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static

3.5
CVE-2021-4274

A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown

3.5
CVE-2022-4631

A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file b

3.5
CVE-2022-4632

A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnera

3.5
CVE-2022-4637

A vulnerability classified as problematic has been found in ep3-bs up to 1.7.x. This affects an unknown part. The manipu

3.5
CVE-2022-4638

A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects

3.5
CVE-2022-4642

A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the compon

3.5
CVE-2022-4735

A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function read

3.5
CVE-2019-25084

A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affec

3.5
CVE-2022-4736

A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown

3.5
CVE-2022-4740

A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the functi

3.5
CVE-2019-25086

A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerabili

3.5
CVE-2019-25088

A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function o

3.5
CVE-2021-4282

A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is a

3.5
CVE-2021-4284

A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up t

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started