CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachmen
Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistic
Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. U
Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each b
Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version
Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows r
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copi
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t
Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Up
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inl
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplie
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent suppli
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u
GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-
GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cros
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) ver
Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to conv
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, thi
A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API e
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerabil
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target bro
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline elem
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted
MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users o
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cr
anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden c
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5,
The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Abso
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a
Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor Cross-Site Scripting Vulnerability A vulnerability in th
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vu
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-r
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started