CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary scrip
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s
Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an au
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi
Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of Java
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st
Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a store
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and
Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at
Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut
Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri
Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started