CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Executio
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could ad
A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authentica
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks
A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may al
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scriptin
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, t
A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.
Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants
Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scri
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the P
Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful
Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options str
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the cli
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited,
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, thi
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited,
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Temp
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab
@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the refe
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4
There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e
A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remot
Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack
HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before versio
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP fr
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susce
Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scrip
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affect
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a mali
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() funct
Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online pri
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started