Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21529

21529 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10485 pojoin h3blog HTTP Header login ppt_log cross site scripting — h3blog 4.3 Medium2025-09-15
CVE-2025-43802 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 5.4AIMediumAI2025-09-15
CVE-2025-6947 WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration — Fireware OS 4.8AIMediumAI2025-09-15
CVE-2025-59332 3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function — 3DAlloy 8.6 High2025-09-15
CVE-2025-43800 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 6.1AIMediumAI2025-09-15
CVE-2025-43791 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 5.4AIMediumAI2025-09-15
CVE-2025-58177 n8n stored cross-site scripting in LangChain Chat Trigger node initialMessages parameter — n8n 5.4 Medium2025-09-15
CVE-2025-58172 drawnix debug logging cross-site scripting vulnerability — drawnix 5.4AIMediumAI2025-09-15
CVE-2025-43794 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 4.8AIMediumAI2025-09-15
CVE-2025-9826 M-Files Hubshare 安全漏洞 — Hubshare 5.4AIMediumAI2025-09-15
CVE-2025-10434 IbuyuCMS Add Article article.php cross site scripting — IbuyuCMS 2.4 Low2025-09-15
CVE-2025-10411 itsourcecode E-Logbook with Health Monitoring System for COVID-19 POST Request check_profile.php cross site scripting — E-Logbook with Health Monitoring System for COVID-19 4.3 Medium2025-09-14
CVE-2025-10388 Selleo Mentingo Create New Course Basic Settings enroll-course cross site scripting — Mentingo 3.5 Low2025-09-14
CVE-2025-10386 Yida ECMS Consulting Enterprise Management System POST Request login.do cross site scripting — ECMS Consulting Enterprise Management System 4.3 Medium2025-09-14
CVE-2025-10373 Portabilis i-Educar educar_turma_tipo_cad.php cross site scripting — i-Educar 3.5 Low2025-09-13
CVE-2025-10372 Portabilis i-Educar educar_modulo_cad.php cross site scripting — i-Educar 3.5 Low2025-09-13
CVE-2025-10370 MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting — RPi-Jukebox-RFID 3.5 Low2025-09-13
CVE-2025-10369 MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting — RPi-Jukebox-RFID 3.5 Low2025-09-13
CVE-2025-10368 MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting — RPi-Jukebox-RFID 3.5 Low2025-09-13
CVE-2025-10367 MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting — RPi-Jukebox-RFID 3.5 Low2025-09-13
CVE-2025-10366 MiczFlor RPi-Jukebox-RFID inc.setWlanIpMail.php cross site scripting — RPi-Jukebox-RFID 3.5 Low2025-09-13
CVE-2025-10340 WhatCD Gazelle Commit Message change_log.php cross site scripting — Gazelle 3.5 Low2025-09-13
CVE-2025-10332 cdevroe unmark info.php cross site scripting — unmark 3.5 Low2025-09-13
CVE-2025-10331 cdevroe unmark Marks.php cross site scripting — unmark 3.5 Low2025-09-13
CVE-2025-10330 cdevroe unmark searchform.php cross site scripting — unmark 4.3 Medium2025-09-12
CVE-2025-43787 Liferay Portal和Liferay DXP 跨站脚本漏洞 — Portal 5.4 -2025-09-12
CVE-2025-9877 Embed Google Datastudio <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Embed Google Datastudio 6.4 Medium2025-09-12
CVE-2025-9879 Spotify Embed Creator <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting — Spotify Embed Creator 6.4 Medium2025-09-12
CVE-2025-10274 erjinzhi 10OA item cross site scripting — 10OA 4.3 Medium2025-09-12
CVE-2025-10272 erjinzhi 10OA catalogue cross site scripting — 10OA 4.3 Medium2025-09-11

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.