CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 u
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and be
A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability wa
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the fi
A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of t
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th
A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi
A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impact
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the fi
A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability i
An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction w
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by
A vulnerability was identified in SapneshNaik Student Management System up to f4b4f0928f0b5551a28ee81ae7e7fe47d9345318.
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of t
A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-
A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file
A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the fi
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the a
A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknow
A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f
A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file
A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct
A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functi
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown f
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the fil
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of
A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The
A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an un
The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could all
A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functiona
A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unk
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/
A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /ad
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/inde
A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the fi
A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /a
A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/e
A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file
A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op
A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started