Skip to main content

About CWE-79

The most common result is disclosure of data such as session cookies, which a script can send elsewhere. Script also runs with the victim's privileges in the site, and combined with other flaws may lead to code execution on the victim's machine.

MITRE name
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Stable
Also known as
XSS, HTML Injection, Reflected XSS / Non-Persistent XSS / Type 1 XSS, Stored XSS / Persistent XSS / Type 2 XSS, DOM-Based XSS / Type 0 XSS, CSS

Mitigations

  • +Use a vetted framework or encoding library that produces properly encoded output.
  • +Encode output for its exact context, since HTML body, attributes, URIs, JavaScript and CSS each need different encoding.
  • +Use structured mechanisms that enforce separation between data and code.
  • +Repeat client-side checks on the server.
  • +Keep client state and sensitive data on the server side where possible to shrink the input surface.

Detection
Automated static analysis has moderate effectiveness, and black box testing with automated test generation can help. Stored XSS is harder to find because the trigger may occur long after the data was stored.

CWE-79 Vulnerabilities

13 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-42897
Microsoft Exchange Server Spoofing Vulnerability
Microsoft8.10.5%KEV2026-05-14
CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Zimbra7.220.2%KEV2026-01-05
CVE-2025-68461
RoundCube Webmail Cross-site Scripting Vulnerability
Roundcube7.226.8%KEV2025-12-18
CVE-2024-11182
Stored XSS vulnerability in MDaemon Email Server
MDaemon5.317.6%KEV2024-11-15
CVE-2020-11023
Potential XSS vulnerability in jQuery
jquery6.984.9%KEV2020-04-29
CVE-2024-43573
Windows MSHTML Platform Spoofing Vulnerability
Microsoft6.546.1%KEV2024-10-08
CVE-2023-5631
Stored XSS vulnerability in Roundcube
Roundcube6.175.9%KEV2023-10-18
CVE-2018-19953
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Systems Inc.6.129.0%KEV2020-10-28
CVE-2018-19943
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Systems Inc.8.021.5%KEV2020-10-28
CVE-2019-18426
WhatsApp Cross-Site Scripting Vulnerability
Facebook8.267.9%KEV2020-01-21
CVE-2019-3929
Crestron Multiple Products Command Injection Vulnerability
Crestron9.899.0%KEV2019-04-30
CVE-2020-3580
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Cisco6.185.6%KEV2020-10-21
CVE-2026-20945
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft4.619.1%2026-04-14

Most Affected Vendors

Related Weaknesses

Frequently Asked Questions

What is CWE-79?→

CWE-79 is the MITRE entry for cross-site scripting. User input ends up in a web page without proper neutralization and runs as script in other users' browsers.

Are reflected, stored and DOM XSS separate CWEs?→

No. MITRE lists them as alternate terms under CWE-79 because they share the same underlying weakness.

How many exploited vulnerabilities are classified as CWE-79?→

This database lists 13 CVE records mapped to CWE-79 by their CVE Numbering Authority. 12 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-42897, CVE-2025-66376, CVE-2025-68461.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.