CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account a
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vuln
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting fr
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting fr
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni
A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This a
A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the functi
A vulnerability has been found in aerouk imageserve and classified as problematic. Affected by this vulnerability is an
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?pa
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue aff
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Aff
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problem
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problemat
A vulnerability, which was classified as problematic, has been found in SourceCodester Cashier Queuing System 1.0.1. Thi
A vulnerability, which was classified as problematic, was found in SourceCodester Cashier Queuing System 1.0. Affected i
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown fu
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this v
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an
A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected b
A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.1.x. Affected is an unkno
A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown
A vulnerability classified as problematic was found in Nakiami Mellivora up to 2.1.x. Affected by this vulnerability is
A vulnerability, which was classified as problematic, was found in JmPotato Pomash. This affects an unknown part of the
A vulnerability was found in HotCRP. It has been rated as problematic. Affected by this issue is some unknown functional
A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of th
A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown proce
Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permission
Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to in
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functiona
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard funct
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Ke
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which all
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functio
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template fun
Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted noteb
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started