Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 8/793
8.2
CVE-2026-54682

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting

8.2
CVE-2026-61824

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:im

8.2
CVE-2026-63135

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Refe

8.2
CVE-2026-47877

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

8.2
CVE-2026-59316

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When usi

8.1
CVE-2025-65110

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design

8.1
CVE-2026-0533

A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by

8.1
CVE-2026-0534

A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site

8.1
CVE-2026-0535

A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cros

8.1
CVE-2026-24490

MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vu

8.1
CVE-2026-2472

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-clo

8.1
CVE-2026-27196

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-a

8.1
CVE-2026-25136

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

8.1
CVE-2026-28272

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway

8.1
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

8.1
CVE-2026-21284

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a

8.1
CVE-2026-21361

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a

8.1
CVE-2026-25529

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un

8.1
CVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu

8.1
CVE-2026-40497

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger

8.1
CVE-2026-43938

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE

8.1
CVE-2026-42897 KEV

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

8.1
CVE-2026-45665

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Sto

8.1
CVE-2026-48149

Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning

8.1
CVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

8.1
CVE-2026-46489

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any

8.1
CVE-2023-45796

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an

8.1
CVE-2026-59795

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

8.1
CVE-2026-47995

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege

8.1
CVE-2026-50758

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c

8.1
CVE-2026-17496

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t

8.1
CVE-2026-48060

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which

8.1
CVE-2026-67328

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling

8.1
CVE-2026-71285

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo

8.1
CVE-2026-48081

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

8.1
CVE-2026-33437

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the G

8.1
CVE-2026-16231

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML esc

8.1
CVE-2026-32257

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo

8.1
CVE-2026-32258

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

8.0
CVE-2025-59158

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri

8.0
CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th

8.0
CVE-2026-22029

React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0,

8.0
CVE-2026-22704

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vul

8.0
CVE-2026-22804

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0

8.0
CVE-2026-1010

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input

8.0
CVE-2026-23997

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro

8.0
CVE-2026-27099

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov

8.0
CVE-2026-22720

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create

8.0
CVE-2026-0752

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 1

8.0
CVE-2026-28405

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started