Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21524

21524 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-63011 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability — WP Hotel Booking 5.9 Medium2025-12-09
CVE-2025-62082 WordPress Generic Elements plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerability — Generic Elements 6.5 Medium2025-12-09
CVE-2025-6923 Reflected XSS in Talent Software's UNIS — UNIS 5.4 Medium2025-12-09
CVE-2025-67557 WordPress WP eBay Product Feeds plugin <= 3.4.9 - Cross Site Scripting (XSS) vulnerability — WP eBay Product Feeds 5.9 Medium2025-12-09
CVE-2025-67558 WordPress Rencontre plugin <= 3.13.7 - Cross Site Scripting (XSS) vulnerability — Rencontre 5.9 Medium2025-12-09
CVE-2025-67556 WordPress Advanced FAQ Manager plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability — Advanced FAQ Manager 5.9 Medium2025-12-09
CVE-2025-67555 WordPress UseStrict's Calendly Embedder plugin <= 1.1.7.2 - Cross Site Scripting (XSS) vulnerability — UseStrict's Calendly Embedder 5.9 Medium2025-12-09
CVE-2025-67553 WordPress Advanced FAQ Manager plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability — Advanced FAQ Manager 6.5 Medium2025-12-09
CVE-2025-67554 WordPress Cookie Notice & Compliance for GDPR / CCPA plugin <= 2.5.8 - Cross Site Scripting (XSS) vulnerability — Cookie Notice & Compliance for GDPR / CCPA 5.9 Medium2025-12-09
CVE-2025-67551 WordPress Wappointment plugin <= 2.6.9 - Cross Site Scripting (XSS) vulnerability — Wappointment 6.5 Medium2025-12-09
CVE-2025-67550 WordPress Donation Thermometer plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability — Donation Thermometer 6.5 Medium2025-12-09
CVE-2025-67549 WordPress oik plugin <= 4.15.3 - Cross Site Scripting (XSS) vulnerability — oik 6.5 Medium2025-12-09
CVE-2025-67552 WordPress Walker Core plugin <= 1.3.17 - Cross Site Scripting (XSS) vulnerability — Walker Core 6.5 Medium2025-12-09
CVE-2025-67545 WordPress FireBox plugin <= 3.1.0-free - Cross Site Scripting (XSS) vulnerability — FireBox 6.5 Medium2025-12-09
CVE-2025-67544 WordPress Shopkeeper Extender plugin < 7.0 - Cross Site Scripting (XSS) vulnerability — Shopkeeper Extender 6.5 Medium2025-12-09
CVE-2025-67543 WordPress Essential Widgets plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability — Essential Widgets 6.5 Medium2025-12-09
CVE-2025-67539 WordPress Select Core plugin < 2.6 - Cross Site Scripting (XSS) vulnerability — Select Core 6.5 Medium2025-12-09
CVE-2025-67538 WordPress JNews Gallery plugin < 12.0.1 - Cross Site Scripting (XSS) vulnerability — JNews Gallery 6.5 Medium2025-12-09
CVE-2025-67541 WordPress WP-ShowHide plugin <= 1.05 - Cross Site Scripting (XSS) vulnerability — WP-ShowHide 6.5 Medium2025-12-09
CVE-2025-67542 WordPress Multi-Step Checkout for WooCommerce plugin <= 2.33 - Cross Site Scripting (XSS) vulnerability — Multi-Step Checkout for WooCommerce 6.5 Medium2025-12-09
CVE-2025-67537 WordPress ThirstyAffiliates plugin <= 3.11.8 - Cross Site Scripting (XSS) vulnerability — ThirstyAffiliates 6.5 Medium2025-12-09
CVE-2025-67536 WordPress LearnPress plugin <= 4.2.9.4 - Cross Site Scripting (XSS) vulnerability — LearnPress 6.5 Medium2025-12-09
CVE-2025-67533 WordPress Themify Portfolio Post plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability — Themify Portfolio Post 7.1 High2025-12-09
CVE-2025-12705 Social Reviews & Recommendations <= 2.5 - Unauthenticated Stored Cross-Site Scripting via Social Media Reviews — Reviews Widgets for Google, Yelp & TripAdvisor 7.2 High2025-12-09
CVE-2025-10876 XSS in Talent Software's e-Bap — e-BAP Automation 5.3 Medium2025-12-09
CVE-2025-6924 Reflected XSS in Talent Software's e-BAP — e-BAP Automation 5.4 Medium2025-12-09
CVE-2025-41695 Reflected XSS vulnerability in dyn_conn.php — FL SWITCH 2005 7.1 High2025-12-09
CVE-2025-41745 Reflected XSS vulnerability in pxc_portCntr2.php — FL SWITCH 2005 7.1 High2025-12-09
CVE-2025-41746 Reflected XSS vulnerability in pxc_portSecCfg.php — FL SWITCH 2005 7.1 High2025-12-09
CVE-2025-41747 Reflected XSS vulnerability in pxc_vlanIntfCfg.php — FL SWITCH 2005 7.1 High2025-12-09

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21524 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.