Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

560
CRITICAL
4,909
HIGH
31,199
MEDIUM
2,399
LOW
39,637 CVEs · Page 94/793
4.3
CVE-2026-10301

A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of

4.3
CVE-2026-32250

NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere

4.3
CVE-2026-10810

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the

4.3
CVE-2026-11337

A vulnerability was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e

4.3
CVE-2026-11436

A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend

4.3
CVE-2026-11512

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unkno

4.3
CVE-2026-11518

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /user

4.3
CVE-2026-12176

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impa

4.3
CVE-2026-12811

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/rou

4.3
CVE-2026-56761

hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to injec

4.3
CVE-2026-13499

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function o

4.3
CVE-2026-13536

A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x.

4.3
CVE-2026-13554

A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an

4.3
CVE-2026-13556

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the f

4.3
CVE-2026-13557

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown co

4.3
CVE-2026-13567

A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr

4.3
CVE-2026-14633

A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d91

4.3
CVE-2026-14634

A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e0139

4.3
CVE-2026-14656

A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of t

4.3
CVE-2026-14704

A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functiona

4.3
CVE-2026-15202

A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzm

4.3
CVE-2026-15492

A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulne

4.3
CVE-2026-15595

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unkno

4.3
CVE-2026-15596

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unkno

4.3
CVE-2026-15715

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i

4.3
CVE-2026-57857

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the Woo

4.3
CVE-2026-16220

A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code o

4.3
CVE-2026-16229

A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown

4.3
CVE-2026-16485

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

4.3
CVE-2026-16486

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f

4.3
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi

4.3
CVE-2026-70596

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user

4.3
CVE-2026-18968

A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue

4.3
CVE-2025-6508

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b

4.3
CVE-2026-19378

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the

4.3
CVE-2026-19998

A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file

4.3
CVE-2026-75077

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

4.3
CVE-2026-75078

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par

4.3
CVE-2026-78054

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function

4.3
CVE-2026-78055

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul

4.3
CVE-2026-78059

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of

4.3
CVE-2026-78060

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t

4.3
CVE-2026-79793

A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown

4.3
CVE-2026-55566

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext

4.3
CVE-2026-55696

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se

4.3
CVE-2026-82554

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c

4.3
CVE-2026-82601

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani

4.2
CVE-2026-54298

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat

4.2
CVE-2026-13957

Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to

4.2
CVE-2026-17739

Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced

Frequently Asked Questions

What is CWE-79?

CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-79?

There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.

How can I protect against CWE-79 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.

Detect CWE-79 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.

Get Started