CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary
GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scri
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to
GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or
GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Stored XS
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Reflected
Contao before 4.5.7 has XSS in the system log.
LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in ap
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaSc
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em
A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib
Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be expl
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a sr
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src a
The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a
The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a
The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a
The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src a
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affe
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XS
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManag
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp.
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the paramet
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started