Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21529

21529 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-34301 IPFire < v2.29 Stored XSS via Location Group Creation — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34316 IPFire < v2.29 Stored XSS via Mail Server Settings — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34305 IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml() — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34310 IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settings — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34315 IPFire < v2.29 Stored XSS via Remote Syslog Server Address — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34302 IPFire < v2.29 Stored XSS via Service Creation — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34314 IPFire < v2.29 Stored XSS via Time Constraint Rule URL Filter — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34313 IPFire < v2.29 Stored XSS via User Quota Rule URL Filter — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-34303 IPFire < v2.29 Stored XSS via Whitelisted Host Creation — IPFire 5.4AIMediumAI2025-10-28
CVE-2025-12335 code-projects E-Commerce Website supplier_update.php cross site scripting — E-Commerce Website 4.3 Medium2025-10-27
CVE-2025-12332 SourceCodester Student Grades Management System admin.php delete_user cross site scripting — Student Grades Management System 2.4 Low2025-10-27
CVE-2025-12334 code-projects E-Commerce Website product_add.php cross site scripting — E-Commerce Website 4.3 Medium2025-10-27
CVE-2025-12333 code-projects E-Commerce Website supplier_add.php cross site scripting — E-Commerce Website 4.3 Medium2025-10-27
CVE-2025-12330 Willow CMS Add Post add cross site scripting — CMS 2.4 Low2025-10-27
CVE-2025-62793 eLabFTW HTML / CSS Injection via Malicious SVG Upload Leads to Credential Theft / Clickjacking — elabftw 6.8 Medium2025-10-27
CVE-2025-62779 Frappe Learning users were able to add HTML through input fields in the Job Form — lms 5.4AIMediumAI2025-10-27
CVE-2025-62263 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 5.4AIMediumAI2025-10-27
CVE-2025-12312 PHPGurukul Curfew e-Pass Management System view-pass-detail.php cross site scripting — Curfew e-Pass Management System 2.4 Low2025-10-27
CVE-2025-12311 PHPGurukul Curfew e-Pass Management System edit-category-detail.php cross site scripting — Curfew e-Pass Management System 2.4 Low2025-10-27
CVE-2025-53533 Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page — web 6.1AIMediumAI2025-10-27
CVE-2025-36138 IBM QRadar SIEM cross-site scripting — QRadar SIEM 6.4 Medium2025-10-27
CVE-2025-36170 IBM QRadar SIEM cross-site scripting — QRadar SIEM 6.4 Medium2025-10-27
CVE-2025-32785 Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field) — web 5.4AIMediumAI2025-10-27
CVE-2025-12303 PHPGurukul Curfew e-Pass Management System admin-profile.php cross site scripting — Curfew e-Pass Management System 2.4 Low2025-10-27
CVE-2025-12302 code-projects Simple Food Ordering System editproduct.php cross site scripting — Simple Food Ordering System 4.3 Medium2025-10-27
CVE-2025-12300 code-projects Simple Food Ordering System addcategory.php cross site scripting — Simple Food Ordering System 4.3 Medium2025-10-27
CVE-2025-12299 code-projects Simple Food Ordering System addproduct.php cross site scripting — Simple Food Ordering System 4.3 Medium2025-10-27
CVE-2025-12298 code-projects Simple Food Ordering System editcategory.php cross site scripting — Simple Food Ordering System 4.3 Medium2025-10-27
CVE-2025-10023 A user with elevated privileges can inject XSS in the Services Meta-services configuration page — Infra Monitoring 6.2 Medium2025-10-27
CVE-2025-12290 Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 359 cross site scripting — Suishang Enterprise-Level B2B2C Multi-User Mall System 4.3 Medium2025-10-27

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.