Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21532

21532 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-7729 Scada-LTS usersProfiles.shtm cross site scripting — Scada-LTS 3.5 Low2025-07-17
CVE-2025-7728 Scada-LTS users.shtm cross site scripting — Scada-LTS 3.5 Low2025-07-17
CVE-2025-53904 The Scratch Channel Has Potential Reflected Cross-Site Scripting (XSS) Vulnerability — the-scratch-channel.github.io 6.1AIMediumAI2025-07-16
CVE-2025-53936 WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `nome_car` — WeGIA 6.1AIMediumAI2025-07-16
CVE-2025-53935 WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `id` — WeGIA 6.1AIMediumAI2025-07-16
CVE-2025-53934 WeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'control.php' parameter 'descricao_emergencia' — WeGIA 5.4AIMediumAI2025-07-16
CVE-2025-47053 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager 5.4 Medium2025-07-16
CVE-2025-53933 WeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'adicionar_enfermidade.php' parameter 'nome' — WeGIA 5.4AIMediumAI2025-07-16
CVE-2025-53932 WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint 'cadastro_adotante.php' parameter 'cpf' — WeGIA 6.1AIMediumAI2025-07-16
CVE-2025-46959 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager 5.4 Medium2025-07-16
CVE-2025-53931 WeGIA vulnerable to Stored Cross-Site Scripting via endpoint `adicionar_raca.php` parameter `raca` — WeGIA 5.4AIMediumAI2025-07-16
CVE-2025-53930 WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint 'adicionar_especie.php' parameter 'especie' — WeGIA 5.4AIMediumAI2025-07-16
CVE-2025-53929 WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint `adicionar_cor.php` parameter `cor` — WeGIA 5.4AIMediumAI2025-07-16
CVE-2025-53926 Emlog has Stored Cross-site Scripting vulnerability due to error — emlog 6.1 Medium2025-07-16
CVE-2025-53925 Emlog has Stored Cross-site Scripting vulnerability in file upload functionality — emlog 5.4 Medium2025-07-16
CVE-2025-53924 Emlog vulnerable to stored Cross-site Scripting in links functionality — emlog 6.9 Medium2025-07-16
CVE-2025-53923 Emlog vulnerable to reflected Cross-site Scripting in admin panel — emlog 8.2 High2025-07-16
CVE-2025-53892 Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerror — vue-i18n 6.1AIMediumAI2025-07-16
CVE-2025-30955 WordPress ListingEasy theme <= 1.9.2 - Reflected Cross Site Scripting (XSS) vulnerability — ListingEasy 7.1 High2025-07-16
CVE-2025-31055 WordPress Electrician - Electrical Service WordPress theme <= 1.0 - Cross Site Scripting (XSS) Vulnerability — Electrician - Electrical Service WordPress 7.1 High2025-07-16
CVE-2025-31072 WordPress Ofiz - Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability — Ofiz - WordPress Business Consulting Theme 7.1 High2025-07-16
CVE-2025-31427 WordPress Invico - WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) Vulnerability — Invico - WordPress Consulting Business Theme 7.1 High2025-07-16
CVE-2025-46500 WordPress Wordpress Auto Spinner plugin <= 3.26.0 - Reflected Cross Site Scripting (XSS) vulnerability — Wordpress Auto Spinner 7.1 High2025-07-16
CVE-2025-47554 WordPress CSS3 Compare Pricing Tables for WordPress plugin <= 11.6 - Reflected Cross Site Scripting (XSS) vulnerability — CSS3 Compare Pricing Tables for WordPress 7.1 High2025-07-16
CVE-2025-47652 WordPress Infility Global plugin <= 2.13.4 - Reflected Cross Site Scripting (XSS) vulnerability — Infility Global 7.1 High2025-07-16
CVE-2025-48291 WordPress Contest Gallery <= 26.0.6 - Cross Site Scripting (XSS) Vulnerability — Contest Gallery 7.1 High2025-07-16
CVE-2025-48345 WordPress Contact Form 7 Editor Button plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability — Contact Form 7 Editor Button 7.1 High2025-07-16
CVE-2025-49031 WordPress SMu Manual DoFollow plugin <= 1.8.1 - Reflected Cross Site Scripting (XSS) vulnerability — SMu Manual DoFollow 7.1 High2025-07-16
CVE-2025-52779 WordPress Dot html,php,xml etc pages plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability — Dot html,php,xml etc pages 7.1 High2025-07-16
CVE-2025-52777 WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Cross Site Scripting (XSS) Vulnerability — Pay with Contact Form 7 7.1 High2025-07-16

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.