CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Dis
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vu
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a sto
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions the
Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a
jsuites is an open source collection of common required javascript web components. In affected versions users are subjec
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to
nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaSc
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package
This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execu
Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a r
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interfa
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in t
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name an
mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management ca
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advance
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTM
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.h
Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflecte
Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are exe
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-si
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scriptin
1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a ba
auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflecte
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: h
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects
Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability o
Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and inc
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability vi
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started