Cyber Resilience

CWE · MITRE source

CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Abstraction: Base · CVEs in our corpus: 47,462

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

There are many variants of cross-site scripting, characterized by a variety of terms or involving different attack topologies. However, they all indicate the same fundamental weakness: improper neutralization of dangerous input between the adversary and a victim.

Last updated: 26 September 2026 07:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 2 mapping(s) from 1 framework(s): CSF 2.0 2 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A05:2025 Injection.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SI-10 Information Input Validation
  • SI-15 Information Output Filtering
  • CA-8 Penetration Testing
  • SA-11 Developer Testing and Evaluation
Detect
Catch it (CSF Detect / Respond)

—

Harden
Shrink the surface (DISA STIG)

—

Validate
Prove the fix (OWASP ASVS)
  • V1.1.2
  • V1.3.2

NIST 800-53 r5 controls that address this weakness (3)AI-assisted

Control Title Family Why it addresses this CWE
SI-10Information Input ValidationSIValidates web inputs to reject script-related content that could produce XSS.
SI-15Information Output FilteringSIOutput validation against expected content can reject or sanitize script content in generated web pages, reducing XSS exploitability.
CA-8Penetration TestingCAPenetration testing submits XSS payloads to web applications, detecting cross-site scripting flaws for subsequent remediation.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-3929 KEV 9.99.80.98952019-04-30
CVE-2022-28368 9.99.80.82442022-04-03
CVE-2023-45138 9.910.00.71162023-10-12
CVE-2022-47523 9.89.80.70582023-01-05
CVE-2025-44148 9.59.80.54712025-06-03
CVE-2023-49785 9.49.10.83162024-03-12
CVE-2021-32671 9.210.00.39742021-06-07
CVE-2024-42009 KEV 9.29.30.82882024-08-05
CVE-2022-25772 9.19.60.62302022-06-20
CVE-2024-28741 9.18.80.78162024-04-06
CVE-2023-34192 KEV 9.09.00.77272023-07-06
CVE-2022-36098 8.98.90.71612022-09-08
CVE-2023-32071 8.99.00.70392023-05-09
CVE-2023-40176 8.99.00.79992023-08-23
CVE-2023-50231 8.99.60.53302024-05-03
CVE-2024-34716 8.99.60.56452024-05-14
CVE-2022-1175 8.88.70.82002022-04-04
CVE-2022-1190 8.88.70.87362022-04-04
CVE-2022-36094 8.88.90.64792022-09-08
CVE-2023-0050 8.88.70.92422023-03-09
CVE-2023-2442 8.88.70.96062023-06-07
CVE-2023-31546 8.89.60.49362023-12-14
CVE-2020-13340 8.78.70.68642020-10-08
CVE-2023-4220 8.78.10.76082023-11-28
CVE-2026-42897 KEV 8.78.10.00522026-05-14