Cyber Resilience

CWE · MITRE source

CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Abstraction: Base · CVEs in our corpus: 46,006

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

There are many variants of cross-site scripting, characterized by a variety of terms or involving different attack topologies. However, they all indicate the same fundamental weakness: improper neutralization of dangerous input between the adversary and a victim.

Last updated: 11 August 2026 21:18 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: full · 7 mapping(s) from 2 framework(s): CAPEC 5 (full) · CSF 2.0 2 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A05:2025 Injection.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SI-10 Information Input Validation
  • SI-15 Information Output Filtering
  • CA-8 Penetration Testing
  • SA-11 Developer Testing and Evaluation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.1.2
  • V1.3.2

NIST 800-53 r5 controls that address this weakness (3)AI-assisted

Control Title Family Why it addresses this CWE
SI-10Information Input ValidationSIValidates web inputs to reject script-related content that could produce XSS.
SI-15Information Output FilteringSIOutput validation against expected content can reject or sanitize script content in generated web pages, reducing XSS exploitability.
CA-8Penetration TestingCAPenetration testing submits XSS payloads to web applications, detecting cross-site scripting flaws for subsequent remediation.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-3929 KEV 9.99.80.98952019-04-30
CVE-2022-28368 9.99.80.82442022-04-03
CVE-2023-45138 9.910.00.71162023-10-12
CVE-2022-47523 9.89.80.70582023-01-05
CVE-2023-49785 9.49.10.83162024-03-12
CVE-2025-44148 9.49.80.52632025-06-03
CVE-2021-32671 9.210.00.39742021-06-07
CVE-2024-42009 KEV 9.29.30.79622024-08-05
CVE-2022-25772 9.19.60.61402022-06-20
CVE-2024-28741 9.18.80.78162024-04-06
CVE-2023-34192 KEV 9.09.00.77272023-07-06
CVE-2022-36098 8.98.90.71042022-09-08
CVE-2023-32071 8.99.00.71142023-05-09
CVE-2023-40176 8.99.00.78882023-08-23
CVE-2023-50231 8.99.60.53302024-05-03
CVE-2024-34716 8.99.60.56172024-05-14
CVE-2022-1175 8.88.70.82002022-04-04
CVE-2022-1190 8.88.70.87362022-04-04
CVE-2023-0050 8.88.70.92422023-03-09
CVE-2023-2442 8.88.70.96062023-06-07
CVE-2023-31546 8.89.60.49362023-12-14
CVE-2020-13340 8.78.70.68642020-10-08
CVE-2022-36094 8.78.90.64102022-09-08
CVE-2023-4220 8.78.10.76082023-11-28
CVE-2026-42897 KEV 8.78.10.70312026-05-14