CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri
Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc
Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field op
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss()
The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJ
The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before ou
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informat
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, secti
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/sr
Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase sugges
OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML pa
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-enco
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authent
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendere
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i
The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a
Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter i
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr
Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative act
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir
MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts
The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be
A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, *
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb
Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr
There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started