Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21529

21529 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12289 Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1001 cross site scripting — Suishang Enterprise-Level B2B2C Multi-User Mall System 4.3 Medium2025-10-27
CVE-2025-50055 OpenVPN Access Server 安全漏洞 — Access Server 6.1AIMediumAI2025-10-27
CVE-2025-12282 code-projects Client Details System manage-users.php cross site scripting — Client Details System 2.4 Low2025-10-27
CVE-2025-12281 code-projects Client Details System clientview.php cross site scripting — Client Details System 2.4 Low2025-10-27
CVE-2025-12280 code-projects Client Details System update-clients.php cross site scripting — Client Details System 2.4 Low2025-10-27
CVE-2025-12279 code-projects Client Details System welcome.php cross site scripting — Client Details System 2.4 Low2025-10-27
CVE-2025-41384 Reflected Cross-Site Scripting (XSS) in SuiteCRM — SuiteCRM 6.1AIMediumAI2025-10-27
CVE-2025-12269 LearnHouse Account Setting previews cross site scripting — LearnHouse 3.5 Low2025-10-27
CVE-2025-12267 abhicodebox ModernShop search cross site scripting — ModernShop 4.3 Medium2025-10-27
CVE-2025-12264 Wisencode Create Support Ticket create cross site scripting — Wisencode 3.5 Low2025-10-27
CVE-2025-12251 OpenWGA Admin UI cross site scripting — OpenWGA 3.5 Low2025-10-27
CVE-2025-11682 Stored Cross-Site Scripting in Perx Customer Engagement & Loyalty Platform — Customer Engagement & Loyalty Platform 5.4AIMediumAI2025-10-27
CVE-2025-12246 chatwoot Admin IframeLoader.vue cross site scripting — chatwoot 4.3 Medium2025-10-27
CVE-2025-12244 code-projects Simple E-Banking System register.php cross site scripting — Simple E-Banking System 4.3 Medium2025-10-27
CVE-2025-12231 projectworlds Expense Management System Expense Categories create cross site scripting — Expense Management System 2.4 Low2025-10-27
CVE-2025-12230 projectworlds Expense Management System Currency create cross site scripting — Expense Management System 2.4 Low2025-10-27
CVE-2025-12229 projectworlds Expense Management System Roles Page create cross site scripting — Expense Management System 2.4 Low2025-10-27
CVE-2025-12228 projectworlds Expense Management System Users Page create cross site scripting — Expense Management System 2.4 Low2025-10-27
CVE-2025-12227 projectworlds Gate Pass Management System add-pass.php cross site scripting — Gate Pass Management System 3.5 Low2025-10-27
CVE-2025-12224 Iqbolshoh php-business-website contact.php cross site scripting — php-business-website 3.5 Low2025-10-27
CVE-2025-48088 WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.1 - Cross Site Scripting (XSS) vulnerability — Ultimate Addons for WPBakery Page Builder 6.5 Medium2025-10-27
CVE-2025-62987 WordPress Builderall Builder for WordPress plugin <= 3.0.1 - Cross Site Scripting (XSS) vulnerability — Builderall Builder for WordPress 6.5 Medium2025-10-27
CVE-2025-62984 WordPress WP AdCenter plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability — WP AdCenter 6.5 Medium2025-10-27
CVE-2025-62985 WordPress Simple Pull Quote plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability — Simple Pull Quote 6.5 Medium2025-10-27
CVE-2025-62983 WordPress Posts By Tag plugin <= 3.2.1 - Cross Site Scripting (XSS) vulnerability — Posts By Tag 6.5 Medium2025-10-27
CVE-2025-62982 WordPress Dynamic User Directory plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability — Dynamic User Directory 5.9 Medium2025-10-27
CVE-2025-62974 WordPress Headline Analyzer plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability — Headline Analyzer 6.5 Medium2025-10-27
CVE-2025-62971 WordPress Attesa Extra plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerability — Attesa Extra 6.5 Medium2025-10-27
CVE-2025-62969 WordPress NextMove Lite plugin <= 2.23.0 - Cross Site Scripting (XSS) vulnerability — NextMove Lite 6.5 Medium2025-10-27
CVE-2025-62967 WordPress DirectoryPress plugin <= 3.6.25 - Cross Site Scripting (XSS) vulnerability — DirectoryPress 6.5 Medium2025-10-27

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.