CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporte
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i
In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript i
FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-
Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious con
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker
Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on bro
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process
jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functi
A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file ro
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functi
A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t
A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio
A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affect
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affect
A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil
A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the co
A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknow
A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknow
P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1
A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona
A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the fil
A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /syst
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t
A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the fil
A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller
A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blosso
A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file t
A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti
A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.
A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/mai
A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/asse
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started