CWE-79Base13 in KEV

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stable in the CWE catalog · 24,491 CVEs mapped

24,491
CVEs mapped
13
In KEV
6.3
Median CVSS
What it is

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Recent examples
3.5cvss
CVE-2026-86491

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

LOWno explanation yet
epss
4.6cvss
CVE-2026-86484

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

MEDIUMno explanation yet
epss
5.4cvss
CVE-2026-86483

In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-79
Abstraction
Base
Structure
Simple
Status
Stable
References (18)