CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups se
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit
Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds,
Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scriptin
Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulti
Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remot
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attac
Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana
Courier Management System 1.0 - 'First Name' Stored XSS
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describi
In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web ap
Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI version
An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post tit
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary w
Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary we
Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to i
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page vi
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows
Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FI
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross
Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t
Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started