CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:im
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Refe
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When usi
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design
A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by
A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site
A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cros
MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vu
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-clo
Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-a
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un
ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Sto
Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any
A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the G
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML esc
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0,
HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vul
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input
FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 1
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started